Drooid Logo
Back to story perspectives

Full Breakdown

Iranian-Linked Cyber Intrusions Target Small Colorado Water Utilities

By Drooid · · How we work

Incident Overview

State officials confirmed that late last month foreign actors accessed the computer systems of two private water utilities in Colorado. Each provider serves fewer than 200 customers. The intrusions involved changes to equipment settings, disabling of remote-access controls and alarms, and alteration of pumping cycles. Providers quickly restored control, alerted the governor’s office, and reported that treatment processes and water quality were not affected.

Background on Foreign Cyber Threats to Water Infrastructure

During the summer, a wave of cyber activity was attributed to Iran, though officials have not confirmed Iranian involvement. At least a dozen states have reported possible intrusions targeting water and wastewater utilities. Federal agencies, including the FBI, have warned that Iranian-affiliated groups are seeking to disrupt U.S. water and energy systems and have urged utilities to disconnect internet-connected controllers, use breaker-protected equipment, and be prepared to operate manually.

Official Statements & Responses

Governor Jared Polis’s office, through spokeswoman Ally Sullivan, said the state is monitoring national trends and is encouraging Colorado providers to double-check security measures and apply necessary updates. An FBI spokesperson declined to comment on investigative details.

Data & Statistics

  • Two water utilities affected, each serving fewer than 200 people.
  • Reports of cyber intrusions span at least twelve states.
  • The incidents were brief; no water-quality impact was recorded.

Verbatim Quotes

  • “We cannot confirm what foreign actors may have been involved, but we are aware of ongoing efforts across the nation by an Iranian-backed group to access drinking water and wastewater systems, as per the Cybersecurity and Infrastructure Security Agency,” — Ally Sullivan, polis spokeswoman