Hackers breach two Colorado water utility companies
The attackers didn’t exactly make a splash.

Image by Bilanol | Shutterstock
- A foreign threat actor briefly accessed two private Colorado water utilities serving about 200 people.
- Officials said water treatment and water quality were never at risk during the incidents.
- Intruders changed settings, disabled remote access and alarms, and altered pumping cycles.
- Colorado is sending new guidance and urging providers to review security updates.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A foreign threat actor briefly gained access to 2 small water utility systems in Colorado last month.
According to state officials, both water utilities are private and serve only about 200 people. During the hack, the water treatment process and water quality were never at risk.
“These 2 incidents consisted of individuals changing equipment settings, disabling remote access and alarms, and altering pumping cycles. These were brief incidents, and the risks were quickly addressed by the providers themselves, who subsequently alerted the state,” a spokesperson for Governor Jared Polis told The Denver Post in a statement.
The Governor’s office can’t confirm what threat actor was involved, but says that it’s aware of previous attempts by Iranian-backed hackers to compromise drinking water and wastewater systems.
In late July, pro-Iranian hacktivist group the CyberAv3ngers targeted more than 30 water and wastewater companies in Minnesota in a coordinated cyberattack. Officials described the events as one of the largest attacks on Minnesota’s water infrastructure in history.
Minnesota IT Services (MNIT) had been working closely with the Minnesota Department of Public Safety, the FBI, and other state and federal authorities to “support affected communities and strengthen the security of the state’s critical infrastructure.”
In early August, the US Cybersecurity and Infrastructure Security Agency (CISA) urged owners and operators of critical infrastructure companies to remove all publicly exposed programmable logic controllers (PLCs) and other operational technology (OT) from the internet as soon as possible.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC,” the cybersecurity agency recommended.
Around the same time, former intelligence officials and cybersecurity experts told The New York Times that the Iranian hackers most likely operated opportunistically rather than targeting specific US infrastructure.
Governor Polis’ spokesperson told The Denver Post that the state is monitoring national trends and recommending that Colorado providers double-check their security measures and updates.
As of writing, Governor Polis’ office is distributing new guidance to state agencies to minimize the risks of hackers gaining access to water utilities’ systems.