Foreign hackers breached operational technology systems at two private Colorado water utilities in late August, according to a spokesperson for Colorado Governor Jared Polis who spoke to The Denver Post.
The attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles at the facilities. Officials said the incidents were brief and quickly addressed. Treatment processes, water quality and public safety were not affected.
The CISA said more than 100 internet-exposed water systems were targeted in July, with activity focused on OT including programmable logic controllers.
John Strand, Owner, Black Hills Information Security:
“I think everything happening with AI is absolutely important, and people should be paying attention to it. But I truly feel like the AI news cycle has completely overwhelmed the targeting of critical infrastructure in the United States.
“For a long time, it seemed like many nation-states were avoiding direct attacks against critical infrastructure, at least at the rate we’re seeing now. It increasingly feels like the gloves are off. We’ve seen municipalities disrupted by cyberattacks, and we’re seeing water and other critical infrastructure targeted and compromised.
“This isn’t something critical infrastructure operators can fix overnight. Many of the security programs these organizations need take months, sometimes years, to properly implement. We were caught flat-footed. We need to start taking action now, because building that defensive capability is going to take time.”
Damon Small, Board of Directors, Xcape Inc.:
“Direct manipulation of operational technology in critical infrastructure threatens physical reliability, regulatory compliance, and public trust long before water quality is compromised. Cyberattacks against Colorado water utilities highlight a distinct shift in state-sponsored tactics, moving past initial proof of concept access to actively probing operators’ response capabilities. Despite many critical changes having been made to remote access, alerting, and pump cycles, the human operators detected the anomalies and responded quickly, mitigating the incident.
“Broad access to Internet-exposed programmable logic controllers is now an established reality, making the central threat no longer whether adversaries can gain unauthorized entry, but how rapidly the victim organization contains the breach once inside. Security leaders must move past basic perimeter defense by removing control interfaces from the public Internet, enforcing multi-factor authentication across all remote access gateways, and isolating industrial control networks behind strict firewalls.
“Critical Takeaways
- Adversaries have escalated from opportunistic probing to evaluating operational incident response capabilities in real time.
- Despite attackers altering critical configurations, rapid human detection prevented physical impact, highlighting the necessity of agile response.
- Executives must enforce strict network segmentation, eliminate direct remote management, and isolate industrial control panels behind multi-factor gateways.
“Proving adversaries can break in is old news; the real test is whether your team can kick them out before the pumps change cycles.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“A utility serving fewer than 200 people cannot fund a security engineer. Foreign actors hit two private Colorado water plants that size in late August, changed pump cycles, disabled alarms, and cut remote access the on-call operator relied on to check the plant. Governor Jared Polis’ office says treatment and water quality held after the providers drove out and reset the controllers.
“Minnesota was July, the Cybersecurity and Infrastructure Security Agency (CISA) counted more than 100 internet-exposed water targets the same month, and Colorado was August. Controller-focused hits on U.S. water are common enough now that defenders should execute CISA’s July guidance on internet-facing programmable logic controllers (PLCs), inventory external access, and pull anything you cannot actively monitor offline.
“OpenAI’s Daybreak for Frontline Defenders and the OpenAI-led industry letter on critical infrastructure both try to put AI on the defender’s side for water utilities. I want that help aimed at plants like these. Model credits only matter if someone on payroll can review a change to a live treatment process without breaking it, which is why the Multi-State Information Sharing and Analysis Center (MS-ISAC) training piece in Daybreak matters as much as the subsidy.
“Federal funding should cover those salaries first, then stack the private-sector offers on top. The pacing from Minnesota to Colorado says defenders should plan for the next wave now.”
While this is a priority of a bunch of priorities, this is big and needs attention ASAP. Because this is already trending in a bad direction.
Related
This entry was posted on September 21, 2026 at 4:12 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Hackers manipulate operational systems at Colorado water utilities
Foreign hackers breached operational technology systems at two private Colorado water utilities in late August, according to a spokesperson for Colorado Governor Jared Polis who spoke to The Denver Post.
The attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles at the facilities. Officials said the incidents were brief and quickly addressed. Treatment processes, water quality and public safety were not affected.
The CISA said more than 100 internet-exposed water systems were targeted in July, with activity focused on OT including programmable logic controllers.
John Strand, Owner, Black Hills Information Security:
“I think everything happening with AI is absolutely important, and people should be paying attention to it. But I truly feel like the AI news cycle has completely overwhelmed the targeting of critical infrastructure in the United States.
“For a long time, it seemed like many nation-states were avoiding direct attacks against critical infrastructure, at least at the rate we’re seeing now. It increasingly feels like the gloves are off. We’ve seen municipalities disrupted by cyberattacks, and we’re seeing water and other critical infrastructure targeted and compromised.
“This isn’t something critical infrastructure operators can fix overnight. Many of the security programs these organizations need take months, sometimes years, to properly implement. We were caught flat-footed. We need to start taking action now, because building that defensive capability is going to take time.”
Damon Small, Board of Directors, Xcape Inc.:
“Direct manipulation of operational technology in critical infrastructure threatens physical reliability, regulatory compliance, and public trust long before water quality is compromised. Cyberattacks against Colorado water utilities highlight a distinct shift in state-sponsored tactics, moving past initial proof of concept access to actively probing operators’ response capabilities. Despite many critical changes having been made to remote access, alerting, and pump cycles, the human operators detected the anomalies and responded quickly, mitigating the incident.
“Broad access to Internet-exposed programmable logic controllers is now an established reality, making the central threat no longer whether adversaries can gain unauthorized entry, but how rapidly the victim organization contains the breach once inside. Security leaders must move past basic perimeter defense by removing control interfaces from the public Internet, enforcing multi-factor authentication across all remote access gateways, and isolating industrial control networks behind strict firewalls.
“Critical Takeaways
“Proving adversaries can break in is old news; the real test is whether your team can kick them out before the pumps change cycles.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“A utility serving fewer than 200 people cannot fund a security engineer. Foreign actors hit two private Colorado water plants that size in late August, changed pump cycles, disabled alarms, and cut remote access the on-call operator relied on to check the plant. Governor Jared Polis’ office says treatment and water quality held after the providers drove out and reset the controllers.
“Minnesota was July, the Cybersecurity and Infrastructure Security Agency (CISA) counted more than 100 internet-exposed water targets the same month, and Colorado was August. Controller-focused hits on U.S. water are common enough now that defenders should execute CISA’s July guidance on internet-facing programmable logic controllers (PLCs), inventory external access, and pull anything you cannot actively monitor offline.
“OpenAI’s Daybreak for Frontline Defenders and the OpenAI-led industry letter on critical infrastructure both try to put AI on the defender’s side for water utilities. I want that help aimed at plants like these. Model credits only matter if someone on payroll can review a change to a live treatment process without breaking it, which is why the Multi-State Information Sharing and Analysis Center (MS-ISAC) training piece in Daybreak matters as much as the subsidy.
“Federal funding should cover those salaries first, then stack the private-sector offers on top. The pacing from Minnesota to Colorado says defenders should plan for the next wave now.”
While this is a priority of a bunch of priorities, this is big and needs attention ASAP. Because this is already trending in a bad direction.
Share this:
Like this:
Related
This entry was posted on September 21, 2026 at 4:12 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.