Foreign Hackers Manipulate Equipment in Colorado Water Utilities
Two privately owned Colorado water utilities, each serving fewer than 200 people, had their equipment settings manipulated by foreign hackers in late August, according to a spokesperson for Colorado's governor. The intruders reportedly disabled remote access and alarms and altered pumping cycles, but officials said the incidents were brief, quickly addressed by the providers, and did not affect treatment processes or water quality.
While authorities have not confirmed exactly who was responsible, officials noted awareness of ongoing efforts by an Iranian-backed group targeting drinking water and wastewater systems across the United States. The incidents follow a broader wave of attacks in August affecting around 100 water entities across roughly a dozen states, flagged in an advisory from the US Cybersecurity and Infrastructure Security Agency. Earlier attacks reportedly targeted programmable logic controllers, industrial devices used to manage critical infrastructure equipment, sometimes resulting in loss of visibility or control over connected systems.
While this incident occurred in the US, it highlights a pattern of attacks against small, resource-limited utility operators that also exists in Australia, where similar critical infrastructure providers may lack dedicated cybersecurity staff.