News

Hackers Hit Two Colorado Water Plants, Tweaked OT Settings, and Disabled Critical Alarms

Colorado officials say attackers reached the control systems at two private water utilities in late August, changing equipment settings, disabling alarms, and altering pumping cycles at plants serving fewer than 200 people combined.

Hackers Hit Two Colorado Water Plants, Tweaked OT Settings, and Disabled Critical Alarms

Attackers got into the control systems at two private water utilities in Colorado in late August and started turning knobs. They changed equipment settings, disabled remote access and alarms, and altered pumping cycles, a spokesperson for Governor Jared Polis told SecurityWeek.

This was not data theft. It was hands on the operational technology that keeps water moving, the kind of intrusion that can cause physical disruption rather than just a leaked database.

The plants are small. Together the two utilities serve fewer than 200 people, and the governor's office says the disruptions were brief and did not affect water service or public safety. The alarms being switched off is the part that should worry other operators, because alarms are what tell a plant something is wrong before it becomes dangerous.

Few technical details are public. The governor's office has not named the utilities, has not confirmed ransomware, and described whoever did this only as "foreign actors." Its spokesperson noted ongoing efforts by an Iranian-backed group to reach drinking water and wastewater systems, flagged by CISA, but stopped short of tying the Colorado plants to that campaign.

That campaign is real and broad. CISA has said it is aware of 100 internet-exposed water systems targeted in July, with confirmed victims across Minnesota, Michigan, Georgia, South Dakota, New Jersey, Wisconsin, and Alabama. The Colorado cases fit the pattern of exposed control systems being poked at, even if attribution stays open.

Small utilities are the soft underbelly here. They run the same kinds of programmable controllers that get exploited elsewhere, as the CISA advisory on internet-facing Siemens S7 PLCs showed, but rarely have a security team to match. Serving a few hundred people does not buy an attacker much leverage, which makes these two plants look less like a payday and more like target practice.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free