← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Two Colorado water utilities were targeted in late August.
  • Attackers changed equipment settings and disabled remote access.
  • No disruption to water services or public safety occurred.
  • CISA urged water sector to secure OT after these attacks.

Cyberattacks on Colorado Water Utilities

In late August, two private water utilities in Colorado were subjected to cyberattacks targeting their operational technology (OT) systems. These utilities serve fewer than 200 people. The attacks involved changes to equipment settings, disabling of remote access and alarms, and alterations to pumping cycles.

Limited Impact and Unidentified Attackers

Despite the attempts to disrupt operations, the incidents were brief and did not affect water services or public safety. The Colorado governor’s office has not identified the affected utilities or the perpetrators, only describing them as “foreign actors.” While an Iranian-backed group has been mentioned in connection with ongoing efforts to access water systems nationwide, it has not been confirmed that these specific Colorado incidents are part of that campaign.

Broader Context of Water Sector Attacks

These attacks in Colorado are part of a larger trend, as the water sector has seen similar incidents in at least a dozen states across the United States in July. Confirmed targets include facilities in Minnesota, Michigan, Georgia, South Dakota, New Jersey, Wisconsin, and Alabama. The Cybersecurity and Infrastructure Security Agency (CISA) has noted awareness of 100 internet-exposed water systems targeted in cyberattacks during July.

Call for Enhanced Security

In response to these incidents, CISA has urged the water sector to enhance the security of their OT systems. The independent security group Infracritical has also established a central repository to aggregate technical indicators and operational data from the recent water sector breaches, aiming to aid in understanding and mitigating future threats.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Two small private water utilities in Colorado experienced cyberattacks in late August that targeted their operational technology (OT) systems. The attacks altered equipment settings and disabled remote access, but did not disrupt water services or public safety. This incident follows a series of similar attacks on water systems across multiple US states, prompting CISA to urge the water sector to secure OT.