Overview
- State officials say two private Colorado water providers that each serve fewer than 200 people were breached in late August and the incidents were brief and quickly discovered.
- The attackers altered equipment control settings, disabled remote access and alarms, and changed pumping cycles, but there is no confirmed impact on water treatment or water quality.
- The affected utilities notified state authorities, the Colorado Department of Public Health and Environment confirmed resolution and offered technical help, and providers restored normal operations.
- Attribution remains unconfirmed: the governor’s office described the perpetrators as "foreign actors" and cited CISA reporting of Iranian‑linked activity, but officials have not formally tied these breaches to the July campaign.
- The incidents echo a wider July pattern that hit about 100 internet‑exposed water control systems and prompted CISA’s August guidance to find and secure programmable logic controllers and other exposed industrial control devices while groups like Infracritical and the EPA compile indicators and offer support.