Overview
- Two privately owned Colorado water systems reported cyber intrusions in late August and operators regained control after quickly taking action and notifying state regulators.
- State officials say attackers altered equipment settings, disabled remote access and alarms, and changed pumping cycles at the affected sites.
- Colorado authorities and the Department of Public Health and Environment report no confirmed impact to treatment processes or drinking water quality at either provider.
- Federal agencies have linked this activity to a wider wave of attacks this year that affected more than 100 U.S. water and wastewater systems and often involved internet‑exposed programmable logic controllers, weak authentication, and lost monitoring or control.
- The incidents highlight gaps at small utilities—older control equipment, limited cybersecurity staff, and scarce funding—and have renewed calls for binding security standards, emergency grants, and shared technical assistance to protect vulnerable communities.