top of page

When Hackers Turned Off the Tap

Writer: Ben Card
Ben Card
5 days ago
5 min read

What the Colorado Water Utility Intrusions Mean for Every U.S. Organization

Water purifier tap filling glass in the red

The Incident: What Happened in Colorado

In late August 2026, unidentified intruders, described by Colorado state officials only as "foreign actors", gained unauthorized access to the operational technology controlling two small, privately owned drinking water utilities in the state. Each serves fewer than two hundred residents. The incidents, first reported by Axios and later summarized by DataBreaches.net, involved changes to equipment settings, the disabling of remote access and alarm functions, and alterations to pumping cycles inside systems meant to keep tap water flowing safely to homes and businesses.

 

Ally Sullivan, a spokesperson for Governor Jared Polis's office, told reporters that the disruptions were brief and caused no known impact to water treatment, water quality, or public safety. In addition state health officials worked directly with the affected utilities to resolve the intrusions and provide technical assistance. Sullivan also said the state could not confirm exactly which foreign actors were responsible, though she noted that federal agencies have been tracking Iranian backed groups with a documented interest in American water infrastructure. Denver Water, which serves roughly 1.5 million people in the metro area, confirmed its own systems were untouched. The state urged other Colorado water providers to review their remote access controls in the wake of the incident.

 

Part of a Larger Pattern: Nation-State Interest in U.S. Water Infrastructure

Flooded road with yellow sign “Water over road"

The Colorado intrusions did not happen in isolation. Reporting on the incident noted that at least a dozen states have experienced some form of water system cyberattack in recent years. Just weeks earlier the FBI's Internet Crime Complaint Center issued a public alert warning that malicious actors were targeting internet facing programmable logic controllers at water and wastewater facilities across multiple states, in some cases causing water pressure loss and localized flooding. Separately, federal agencies have spent the past two years warning that state-sponsored groups such as Volt Typhoon have pre-positioned themselves inside U.S. critical infrastructure networks, including water systems, not necessarily to cause immediate damage, but to maintain the ability to disrupt operations during a future crisis.

 

What makes small utilities like the two in Colorado attractive is precisely because of their size. Serving a few hundred customers rarely comes with a dedicated cybersecurity staff, a security operations center, or the budget to replace aging industrial control equipment on a modern refresh cycle. Organizations like WaterISAC exist specifically to close that gap by sharing threat intelligence and practical guidance across a sector where thousands of operators are individually too small to track nation-state activity on their own, but collectively represent a critical piece of the country's public health infrastructure.

 

These are precisely the kinds of controls that, had they been fully in place, might have limited how far the Colorado intruders could reach once inside.

The Regulatory and Oversight Landscape for Water Sector Cybersecurity

Unlike sectors such as banking or publicly traded companies, water utilities in the United States do not answer to a single cybersecurity regulator with binding technical mandates. Instead, the EPA serves as the federal Sector Risk Management Agency for water and wastewater systems, offering free cybersecurity assessments, technical assistance, and incident response planning tools aimed at utilities of every size. CISA plays a complementary role, designating water and wastewater as one of the nation's critical infrastructure sectors and publishing threat advisories, but responsibility for actually securing most systems still rests with individual utilities. Many of these are municipally owned or, as in Colorado's case, small private operators with limited resources.

 

To help close that gap, CISA has published a set of Cross-Sector Cybersecurity Performance Goals specifically designed for small and under-resourced critical infrastructure operators who cannot realistically implement an exhaustive security program overnight. The goals prioritize a short list of high-impact practices, such as maintaining an asset inventory, enforcing strong credential management, segmenting operational technology networks from business IT, and having a basic incident response plan in place. These are precisely the kinds of controls that, had they been fully in place, might have limited how far the Colorado intruders could reach once inside.


Utility Meters on a brick wall

Broader Lessons for Businesses and Organizations Beyond Water Utilities

It is tempting for a manufacturer, hospital system, logistics company, or professional services firm to read a story about rural water utilities and conclude it has nothing to do with them. That would be a mistake. The pattern in Colorado is exactly the same pattern that plays out in manufacturing plants, building automation systems, medical device networks, and warehouse and logistics equipment across the country. Unauthenticated or loosely secured remote access into equipment that controls a physical process, alarms, and monitoring are quietly switched off and settings changed without anyone noticing right away. Any organization that lets vendors, contractors, or employees reach operational equipment remotely, and any organization that has never separated that equipment from its everyday business network, carries a version of the same exposure.

 

The other lesson is about assumptions. Utilities serving under two hundred customers likely never expected to be a target of foreign intrusion, in much the same way that many small and mid-sized businesses assume they are too unimportant to attract sophisticated attackers. Attackers, and particularly state-linked groups engaged in long-term positioning, do not always pick targets based on size or prominence. Sometimes a small, under-defended network is chosen precisely because it is small and under-defended. Whether the eventual goal is disruption, a foothold for lateral movement, or simply a low-risk place to test techniques before using them elsewhere, any network size is at risk.

 

What Organizations Should Do Now

Organizations that operate any kind of connected equipment, whether that is industrial control systems, building management platforms, medical devices, or even internet-connected office equipment, should treat the Colorado incident as a prompt to revisit the basics. That means maintaining a current inventory of what is connected to the network and who can reach it remotely, removing or tightly restricting remote access accounts that are not actively needed, enabling multifactor authentication everywhere it is supported, separating operational technology from general business networks, and making sure alarms and monitoring cannot be silently disabled without triggering a separate alert. It also means having a written incident response plan that has actually been tested, not one that only exists on paper.

 

None of this has to be figured out alone. If your organization wants help assessing where similar gaps might exist in your own network, whether that involves operational technology, remote access, or the broader security controls that regulators and insurers increasingly expect, the team at Webcheck Security is available to help you evaluate your exposure and build a practical plan to close it. You can reach us anytime through our contact page to get started.



 
 
 

Comments


bottom of page