Foreign hackers breached operational technology systems at two private Colorado water utilities in late August, according to a spokesperson for Colorado Governor Jared Polis who spoke to The Denver Post.
The attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles at the facilities. Officials said the incidents were brief and quickly addressed. Treatment processes, water quality and public safety were not affected.
The CISA said more than 100 internet-exposed water systems were targeted in July, with activity focused on OT including programmable logic controllers.
John Strand, Owner, Black Hills Information Security:
“I think everything happening with AI is absolutely important, and people should be paying attention to it. But I truly feel like the AI news cycle has completely overwhelmed the targeting of critical infrastructure in the United States.
“For a long time, it seemed like many nation-states were avoiding direct attacks against critical infrastructure, at least at the rate we’re seeing now. It increasingly feels like the gloves are off. We’ve seen municipalities disrupted by cyberattacks, and we’re seeing water and other critical infrastructure targeted and compromised.
“This isn’t something critical infrastructure operators can fix overnight. Many of the security programs these organizations need take months, sometimes years, to properly implement. We were caught flat-footed. We need to start taking action now, because building that defensive capability is going to take time.”
Damon Small, Board of Directors, Xcape Inc.:
“Direct manipulation of operational technology in critical infrastructure threatens physical reliability, regulatory compliance, and public trust long before water quality is compromised. Cyberattacks against Colorado water utilities highlight a distinct shift in state-sponsored tactics, moving past initial proof of concept access to actively probing operators’ response capabilities. Despite many critical changes having been made to remote access, alerting, and pump cycles, the human operators detected the anomalies and responded quickly, mitigating the incident.
“Broad access to Internet-exposed programmable logic controllers is now an established reality, making the central threat no longer whether adversaries can gain unauthorized entry, but how rapidly the victim organization contains the breach once inside. Security leaders must move past basic perimeter defense by removing control interfaces from the public Internet, enforcing multi-factor authentication across all remote access gateways, and isolating industrial control networks behind strict firewalls.
“Critical Takeaways
- Adversaries have escalated from opportunistic probing to evaluating operational incident response capabilities in real time.
- Despite attackers altering critical configurations, rapid human detection prevented physical impact, highlighting the necessity of agile response.
- Executives must enforce strict network segmentation, eliminate direct remote management, and isolate industrial control panels behind multi-factor gateways.
“Proving adversaries can break in is old news; the real test is whether your team can kick them out before the pumps change cycles.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“A utility serving fewer than 200 people cannot fund a security engineer. Foreign actors hit two private Colorado water plants that size in late August, changed pump cycles, disabled alarms, and cut remote access the on-call operator relied on to check the plant. Governor Jared Polis’ office says treatment and water quality held after the providers drove out and reset the controllers.
“Minnesota was July, the Cybersecurity and Infrastructure Security Agency (CISA) counted more than 100 internet-exposed water targets the same month, and Colorado was August. Controller-focused hits on U.S. water are common enough now that defenders should execute CISA’s July guidance on internet-facing programmable logic controllers (PLCs), inventory external access, and pull anything you cannot actively monitor offline.
“OpenAI’s Daybreak for Frontline Defenders and the OpenAI-led industry letter on critical infrastructure both try to put AI on the defender’s side for water utilities. I want that help aimed at plants like these. Model credits only matter if someone on payroll can review a change to a live treatment process without breaking it, which is why the Multi-State Information Sharing and Analysis Center (MS-ISAC) training piece in Daybreak matters as much as the subsidy.
“Federal funding should cover those salaries first, then stack the private-sector offers on top. The pacing from Minnesota to Colorado says defenders should plan for the next wave now.”
While this is a priority of a bunch of priorities, this is big and needs attention ASAP. Because this is already trending in a bad direction.
Trump announces new federal “AI Force” as industry leaders raise concerns about AI risks
Posted in Commentary with tags The White House on September 21, 2026 by itnerdPresident Donald Trump has announced plans to create a new federal “AI Force” focused on artificial intelligence, according to The Wall Street Journal.
Trump compared the initiative to the creation of the U.S. Space Force and said he will appoint a new AI czar. The administration has not yet disclosed how the AI Force will be structured, funded or what specific authority it will have.
The announcement comes as AI executives call for additional safety measures. Trump has opposed broad new restrictions on AI development, arguing that existing criminal and civil laws can address harmful uses of the technology.
Doc McConnell, Head of Policy and Compliance, Finite State:
“Let’s not overcomplicate the question of AI regulation. In every other sector of the economy, we hold manufacturers accountable for the safety of what they build: toys, houses, cars. There’s no reason AI should be the exception. Today, what clouds the debate over accountability is that there are multiple actors: the frontier labs that train the models, the companies that deploy them, and the users who prompt them and act on the outputs. That gives everyone a reasonable-sounding excuse. The lab claims that a deployer failed to sandbox the agent, the deployer blames a reckless user, and the user says the underlying model was flawed.
“To ensure that these models are fundamentally safe, there must be meaningful liability for the frontier labs. This liability should apply to the doomsday scenarios we’re hearing about today, like biological agents or cyber attacks against real-world infrastructure. But it should also apply to the harms that we’ve already seen play out: the creation of child sexual abuse material, or the contributions of chatbots to self-harm and suicide. And the liability must be strong enough to counterbalance the enormous commercial incentive for labs to build faster, more responsive, more autonomous models.
“And there can be no compromise to our existing anti-discrimination protections in fields like healthcare and housing. AI is a tool, used by people. Those people must remain accountable for the fair and equitable outcomes of their work, no matter what tools they choose to use.”
Denis Calderone, CTO, Suzu Labs:
“Workable regulation is whatever survives an administration that doesn’t want to regulate, and that narrows it fast to two things, mandatory incident disclosure and clear liability for real-world harm.
“Self-reporting fails for the same reason the SEC has mandatory disclosure and OSHA runs inspections instead of waiting for companies to mail in hazard reports, because the organization with the most to lose is the worst one to decide what the public hears.
“Put people with real security experience in the room. The people who’ve actually built, broken, and hardened production systems, who’ve worked a breach and had to explain to a customer what happened to their data, should be designing these tests and reviewing the findings.”
This isn’t nearly enough as we have AI escaping places right left and center. That required a more substantial response. This isn’t it and the Americans will pay for it. Mark my words.
Leave a comment »