Security1 publisher2 min readPublished
Intruders disabled alarms and altered pumping cycles at two small Colorado water utilities
The governor's office raised an Iranian-backed campaign against drinking water systems and would not say whether the two Colorado utilities hit in late August were part of it. Both remain unnamed.
The Watch · Security desk

What happened
- Intruders targeted the operational technology at two private water utilities in Colorado in late August, apparently trying to cause disruption.
- A spokesperson for Governor Jared Polis told The Denver Post that the attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles.
- The governor's office says the disruptions were brief and did not affect water services or public safety.
- Both utilities are privately run and serve fewer than 200 people. Few technical details have been released about how the industrial control systems were reached.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure CISA's count of 100 internet-exposed water systems targeted in July is the closest public measure of how many plants sit in the same position as the two in Colorado.
- contradiction One statement from the state both invokes the Iranian-backed group and says involvement cannot be confirmed, leaving operators unable to tell campaign activity from opportunistic access.
- constraint The state has not named the utilities, so an operator looking for comparable indicators is working from Infracritical's voluntary repository of data from the recent breaches.
- decision CISA has told the water sector to secure OT. At a utility serving a few hundred people that decision comes down to whether remote access to pumps stays reachable at all.
Changing an equipment setting, switching off an alarm and altering a pumping cycle are operator actions [4]. They need access to the control system. Few technical details have been released, and the public account does not say how the intruders got that access [3]. Two of the reported changes are about visibility. An alarm is how an operator learns that a tank level or a pressure has moved out of band, and remote access is how a small utility looks at the plant without sending someone to it. With both off, a change to the pumping cycle runs unseen [4].
The state stopped short of attributing the intrusions [6]. Its spokesperson raised the Iran-linked activity and then declined to connect it. "We cannot confirm what foreign actors may have been involved, but we are aware of ongoing efforts across the nation by an Iranian-backed group to access drinking water and wastewater systems, as per the Cybersecurity and Infrastructure Security Agency," the spokesperson told The Denver Post [7]. Whether the two Colorado systems belong to that campaign is unconfirmed [8].
The public list of July targets goes state by state and says nothing about system sizes [9]. Two private systems serving fewer than 200 people had their settings, alarms and pumping changed, and the changes were brief enough that water service and public safety were unaffected [1][2][5].
The July activity reached at least a dozen states [8]. Seven have confirmed targets: Minnesota, Michigan, Georgia, South Dakota, New Jersey, Wisconsin and Alabama [9]. Subtract those from twelve and at least five states with confirmed victims remain unnamed [13].
What to watch
- Whether the governor's office names the two utilities or releases indicators from the late-August intrusions.
- Whether CISA or the FBI links the Colorado incidents to the Iranian-backed group behind the July water sector activity.
- Whether Infracritical's repository shows the same access path at the Colorado systems as at the confirmed July victims.