Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
Two Colorado water utilities were targeted in a cyberattack that aimed to disrupt operations by altering industrial control system settings. While the exact actors remain unknown, the incidents align with a broader campaign by Iranian-backed groups targeting water and wastewater systems across the United States. The attacks, though brief, highlight a growing threat to critical infrastructure and prompted a response from federal agencies.
Two private water utilities in Colorado experienced cyberattacks targeting their operational technology (OT) systems in late August. The attacks involved the modification of equipment settings, disabling remote access and alarms, and altering pumping cycles. A spokesperson for Colorado Governor Jared Polis indicated that the attackers were described as "foreign actors." The incidents are part of a larger trend of cyberattacks against water and wastewater systems, with CISA reporting 100 internet-exposed systems targeted in July across at least a dozen states, including Minnesota, Michigan, Georgia, South Dakota, New Jersey, Wisconsin, and Alabama. The Colorado governor’s office has not yet identified the specific utilities involved or named the attackers, only stating that they are investigating ongoing efforts by an Iranian-backed group. Federal authorities, including the FBI and Coast Guard, are also responding to cyberattacks on two oil tankers, further emphasizing the escalating risk to critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) has urged the water sector to bolster its OT security measures in light of these events, and an independent security group, Infracritical, has created a central repository of technical indicators and operational data from these breaches.