Foreign hackers recently executed a cyberattack on two Colorado water utility systems, successfully altering equipment settings, disabling alarms, and changing pumping cycles. While the breach targeted operational technology used to control physical machinery, state officials confirmed that drinking water quality and treatment processes were not compromised. The affected utilities provide water to approximately 400 residents, and providers were able to quickly address the risks and restore control.
How are hackers targeting US water infrastructure?
Federal authorities have warned that malicious actors are increasingly targeting internet-connected operational technology at water and wastewater utilities nationwide. These systems, which manage critical pumps and valves, are vulnerable when exposed directly to the internet. The Environmental Protection Agency has identified over 900 vulnerabilities across more than 650 systems since fiscal year 2025, prompting urgent efforts to strengthen cybersecurity and remove exposed controllers from public networks.
What is the broader impact of these cyberattacks?
The Colorado incidents are part of a widening series of breaches affecting more than 100 drinking water and wastewater systems across 12 states this year. These attacks demonstrate how hackers can reach beyond traditional computer networks to gain access to physical equipment at water plants. In response, federal agencies are working with local utilities to conduct risk assessments and provide technical assistance to secure vulnerable infrastructure against future unauthorized access.