Drooid Logo
Back to story perspectives

Full Breakdown

Colorado Water Utilities Hacked Amid Growing Cyber Threat to U.S. Water Infrastructure

By Drooid · · How we work

Colorado Water Utilities Hacked

State officials confirmed that foreign actors accessed the computer systems of two small Colorado water utilities in late August. The intrusions allowed hackers to change equipment settings, disable remote access and alarms, and alter pumping cycles. Operators regained control quickly, and the utilities reported that drinking-water treatment processes and water quality were not affected. The two private systems together serve fewer than 200 residents each.

Background and Recent Nationwide Threats

The incidents add Colorado to a wave of cyber intrusions targeting U.S. drinking-water and wastewater facilities. The Environmental Protection Agency (EPA) has documented attacks on more than 100 systems across 12 states this year, with at least seven states reporting incidents as early as July. Federal warnings in July highlighted “Iranian-affiliated” actors seeking to disrupt water and energy infrastructure, and similar activity was reported in Minnesota and other states earlier this summer.

Official Responses

  • “We cannot confirm what foreign actors may have been involved, but we are aware of ongoing efforts across the nation by an Iranian-backed group to access drinking water and wastewater systems, as per the Cybersecurity and Infrastructure Security Agency,” — Ally Sullivan, polis spokeswoman
  • EPA – The agency, which serves as the federal sector risk-management authority for water systems, said it is working with utilities, states, and partners to identify and remediate vulnerabilities.
  • FBI – Denver spokeswoman Vikki Migoya declined to comment on investigative details, noting the agency typically does not discuss ongoing cases.

Data on Vulnerabilities and Federal Efforts

Since fiscal year 2025, the EPA has identified more than 900 vulnerabilities at over 650 water systems, helped eliminate about 700 vulnerabilities at more than 500 utilities, conducted over 710 cybersecurity risk assessments, and provided direct technical assistance to roughly 15,900 utilities nationwide.

Implications for Small and Rural Utilities

The Colorado breaches underscore the challenges faced by small, often under-resourced utilities that rely on internet-connected industrial control systems. Federal officials have urged operators to remove programmable logic controllers from direct internet exposure and to strengthen authentication and access controls. As the number of reported incidents grows, the pressure on limited cybersecurity staff at rural utilities is expected to increase, prompting calls for broader federal support and stricter security standards.