LATEST View all updates

Colorado Water Utility Cyberattack: What Hackers Changed and What Was Not Affected

Colorado says foreign actors changed water-utility OT settings and pumps, but water service and quality were unaffected.

Editorial cybersecurity illustration of water utility pumps, OT controls and disabled alarms

Signal Brief

  • Colorado says attackers changed operational settings, disabled remote access and alarms, and altered pumping cycles at two small private water providers.
  • Officials reported no impact to treatment, water quality, water service or public safety.
  • The attacker identity, entry vector and affected OT products remain unknown, so Iran or specific PLC models must not be presented as Colorado facts.
  • Federal guidance urges water utilities to remove publicly exposed OT, validate remote connections and preserve manual operating capability.

The Colorado water utility cyberattack involved real manipulation of operational equipment, but officials say it did not affect drinking-water quality, treatment, water service or public safety. According to Colorado officials, foreign actors accessed operational equipment at two small privately owned water providers in late August, changed equipment settings, disabled remote access and alarms, and altered pumping cycles.

What happened in the Colorado water utility cyberattack?

Colorado officials say two privately owned water providers, each serving fewer than 200 people, experienced brief cyber intrusions involving operational equipment. The attackers changed settings, disabled remote access and alarms, and altered pumping cycles. The providers addressed the incidents quickly and reported them to the state.

The state says treatment processes, water quality, water service and public safety were not affected. The identities of the utilities, the affected equipment and the attackers have not been publicly confirmed.

Infographic separating confirmed Colorado water utility cyberattack facts from unresolved attribution and equipment details
Colorado confirmed OT setting, alarm and pump-cycle changes, while actor identity, equipment and access path remain unknown.

What did the attackers actually change?

The incident went beyond attempted login activity or ordinary office-IT access. Colorado’s account describes direct changes to operational equipment. Three confirmed actions matter most:

  • equipment settings were changed;
  • remote access and alarms were disabled;
  • pumping cycles were altered.

The state has not publicly described the exact pump commands, control logic, PLC models or SCADA components involved, so those details should remain unknown rather than inferred from other water-sector incidents.

Was drinking water contaminated?

No contamination or water-quality impact was reported. Colorado officials said that, to their knowledge, treatment processes and water quality were not affected.

That distinction is important. The attackers reportedly reached operational equipment, but the reviewed evidence does not show that they changed chemical treatment, contaminated drinking water or caused a public-health incident.

Did customers lose water service?

Colorado officials said the incidents did not affect water service or public safety. The two providers resolved the incidents quickly after detecting the activity.

That does not make the intrusions insignificant. Successful access to operational controls can create cyber-physical risk even when operators contain the event before customers experience an outage or unsafe water.

Why does disabling alarms and remote access matter?

Operational alarms and remote-access functions help operators detect abnormal conditions and understand what equipment is doing. If an attacker can suppress alarms while changing settings or pump behavior, operators may lose visibility at the same time the physical process is being manipulated.

Federal water-sector warnings have separately described malicious activity against internet-facing operational technology that caused loss of visibility and, in some cases, forced utilities to use manual operations. Those broader warnings provide relevant defensive context, but they do not prove that the Colorado incidents used the same equipment or attack path.

Was Iran responsible for the Colorado water attacks?

Attribution remains unknown. Colorado said foreign actors were involved but did not identify a country, government or hacking group.

The governor’s office also referenced broader Iranian-backed activity targeting U.S. water systems. That broader threat context must not be converted into incident-specific attribution. The reviewed evidence does not establish that Iranian actors, CyberAv3ngers or another named group carried out the Colorado intrusions.

Which Colorado water utilities were attacked?

The two providers have not been publicly identified in the evidence reviewed by TPS. Officials described them as small privately owned water providers serving fewer than 200 people each.

TPS should not speculate about utility names or infer involvement from geography, ownership type or other cyber incidents. Denver Water separately said it was not affected.

What equipment or PLC models were compromised?

The Colorado incident evidence does not identify the equipment vendor, PLC model, HMI, SCADA platform or remote-access product involved.

This is especially important because separate federal warnings have discussed malicious targeting of internet-facing operational technology and specifically named Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 PLCs in other incidents. That federal product information should not be projected onto the Colorado utilities without incident-specific evidence.

Is this part of the broader U.S. water-sector cyber campaign?

The Colorado incidents occurred during a wider period of malicious targeting of U.S. water and wastewater operational technology. Federal agencies warned in July that utilities in multiple states had reported incidents involving internet-facing PLCs and operational disruption.

However, the reviewed evidence does not technically link the two Colorado incidents to the same actor, infrastructure, exploit path or PLC family described in those federal warnings. The correct current state is therefore: same broader threat environment, specific technical linkage unconfirmed.

What should water utilities check now?

Find internet-exposed OT

Identify PLCs, HMIs, gateways and other operational assets that can be reached directly from the public internet. Current federal guidance urges utilities to remove publicly exposed PLCs and OT where possible.

Validate remote and cellular connections

Review every legitimate external connection into the operational environment, including vendor access, cellular links and remote-maintenance paths. Unknown connectivity should be treated as a security finding.

Review alarms and operator visibility

Confirm that critical alarms, telemetry and remote-access state changes are logged and independently visible so an attacker cannot suppress the only signal operators rely on.

Preserve manual operation

Maintain and test safe manual operating procedures for critical water processes in case remote visibility or automated control is lost during a cyber incident.

Maintain an OT asset inventory

Know which PLCs, HMIs, firmware versions, communications paths and remote-access tools are actually deployed. This makes vendor advisories and incident findings actionable.

Prepare incident-reporting paths

Operators should know how to preserve logs and escalate suspicious OT activity to state authorities and relevant federal cyber or law-enforcement channels.

What is confirmed and what remains unknown?

Question Current evidence state
Were operational settings changed? Confirmed by Colorado officials
Were alarms and remote access disabled? Confirmed by Colorado officials
Were pumping cycles altered? Confirmed by Colorado officials
Was water quality affected? Officials say no known impact
Was water service interrupted? Officials say no
Were the attackers Iranian? Unknown
Which utilities were affected? Not publicly identified
Which PLC or OT products were used? Unknown
Was this technically linked to the wider U.S. PLC campaign? Not established

Colorado water utility cyberattack: direct answers

Did hackers reach operational equipment?

Yes. Colorado says attackers changed equipment settings and altered pumping cycles.

Did hackers contaminate drinking water?

No such impact was reported. Officials said treatment processes and water quality were not affected to their knowledge.

Did customers lose water service?

Colorado said water service and public safety were not affected.

Do officials know who carried out the attack?

No. The state said it could not confirm which foreign actors were responsible.

Were Rockwell MicroLogix PLCs involved?

The reviewed Colorado evidence does not identify the affected equipment. Those PLC models appear in separate federal warnings about other water-sector activity.

Are the Colorado incidents still ongoing?

The reviewed state account says the two providers resolved the incidents quickly. No evidence reviewed by TPS established an ongoing compromise at those two utilities.

Verification method

ThePulseSignal reviewed the Colorado governor-office account carried by current reporting and compared it with FBI, EPA and CISA water-sector OT guidance. TPS kept Colorado-confirmed incident facts separate from broader federal actor and PLC context.

Limitations

The two affected utilities, specific OT products, exact intrusion dates, initial access vector and attacker identity remain undisclosed. Federal warnings about Iranian-linked activity and Rockwell PLCs provide broader threat context but do not establish those facts for the Colorado incidents.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial guidance on the Colorado water utility cyberattack. Colorado officials confirmed operational changes at two small private providers, but the attacker identity, entry method and affected equipment remain unresolved, and broader Iran-linked or PLC-targeting activity must not be treated as Colorado attribution. Verify current Colorado, CISA, FBI and EPA guidance before consequential operational action.