Foreign hackers breach Colorado water utilities as cyberattacks on US infrastructure spread
Cyberattacks on American water and wastewater systems have now touched more than 100 facilities across 12 states this year, according to the Environmental Protection Agency. Foreign actors added Colorado to that count last month,…
Key takeaways
- Foreign hackers breached two small Colorado water utilities last month, altering pumping cycles and disabling alarms before operators regained control, according to Gov. Jared Polis' office.
- Drinking water quality and treatment processes were not affected, and the compromised systems together serve about 400 people.
- Cyberattacks on US water and wastewater systems have touched more than 100 facilities across 12 states this year, per the EPA.
- State officials have not identified the actors behind either Colorado breach or confirmed a link to the broader wave of attacks.
- Since fiscal year 2025 the EPA has identified more than 900 vulnerabilities at over 650 water systems and helped eliminate about 700 of them at more than 500 utilities.
Cyberattacks on American water and wastewater systems have now touched more than 100 facilities across 12 states this year, according to the Environmental Protection Agency. Foreign actors added Colorado to that count last month, breaching two small utilities, altering pumping cycles and disabling alarms before operators regained control, Colorado Gov. Jared Polis' office confirmed Thursday. Drinking water quality and treatment processes were not affected.
The Colorado intrusions reached beyond traditional computer networks to gain access to operational technology controlling physical equipment. Hackers altered equipment settings, disabled remote access and alarms, and changed pumping cycles at systems that together serve approximately 400 people. State officials have not identified the actors behind either breach or confirmed whether the incidents connect to the broader wave of attacks reported elsewhere in the country.
"These were brief incidents, and the risks were quickly addressed by the providers themselves, who subsequently alerted the state," said Eric Maruyama, a spokeswoman for Governor Polis.
A sector-wide exposure problem
The FBI and EPA warned in July that malicious cyber actors were targeting internet-connected operational technology at water and wastewater utilities across the country. By then, facilities in at least seven states had reported incidents, some of which degraded operations. Attackers had remotely accessed internet-facing programmable logic controllers, known as PLCs, and tampered with device configurations, in some cases stripping utilities of monitoring or control capabilities. Reported effects included loss of water pressure and flooding.
Colorado's incidents follow a series of breaches affecting more than 30 community water systems in Minnesota. Federal investigators examined whether Iranian actors were responsible for those attacks, though no public attribution had been made. President Donald Trump disputed that framing during a Cabinet meeting, saying, "They blame it on Iran. I don't think so," and instead pointed to Minnesota officials.
The EPA, which serves as the federal sector risk management agency for water and wastewater systems, said it has identified more than 900 vulnerabilities at over 650 water systems since fiscal year 2025 and helped eliminate roughly 700 of those at more than 500 utilities. The agency has also conducted more than 710 cybersecurity risk assessments and provided direct technical assistance to approximately 15,900 utilities.
Small and rural systems carry the most exposure. Many operate internet-connected industrial control systems with limited dedicated cybersecurity staff. Federal officials have urged operators to remove PLCs from direct internet access and strengthen authentication controls. The FBI declined to comment.
Related reading
Source · 來源