The Colorado water utility cyberattack involved real manipulation of operational equipment, but officials say it did not affect drinking-water quality, treatment, water service or public safety. According to Colorado officials, foreign actors accessed operational equipment at two small privately owned water providers in late August, changed equipment settings, disabled remote access and alarms, and altered pumping cycles.
What happened in the Colorado water utility cyberattack?
Colorado officials say two privately owned water providers, each serving fewer than 200 people, experienced brief cyber intrusions involving operational equipment. The attackers changed settings, disabled remote access and alarms, and altered pumping cycles. The providers addressed the incidents quickly and reported them to the state.
The state says treatment processes, water quality, water service and public safety were not affected. The identities of the utilities, the affected equipment and the attackers have not been publicly confirmed.

What did the attackers actually change?
The incident went beyond attempted login activity or ordinary office-IT access. Colorado’s account describes direct changes to operational equipment. Three confirmed actions matter most:
- equipment settings were changed;
- remote access and alarms were disabled;
- pumping cycles were altered.
The state has not publicly described the exact pump commands, control logic, PLC models or SCADA components involved, so those details should remain unknown rather than inferred from other water-sector incidents.
Was drinking water contaminated?
No contamination or water-quality impact was reported. Colorado officials said that, to their knowledge, treatment processes and water quality were not affected.
That distinction is important. The attackers reportedly reached operational equipment, but the reviewed evidence does not show that they changed chemical treatment, contaminated drinking water or caused a public-health incident.
Did customers lose water service?
Colorado officials said the incidents did not affect water service or public safety. The two providers resolved the incidents quickly after detecting the activity.
That does not make the intrusions insignificant. Successful access to operational controls can create cyber-physical risk even when operators contain the event before customers experience an outage or unsafe water.
Why does disabling alarms and remote access matter?
Operational alarms and remote-access functions help operators detect abnormal conditions and understand what equipment is doing. If an attacker can suppress alarms while changing settings or pump behavior, operators may lose visibility at the same time the physical process is being manipulated.
Federal water-sector warnings have separately described malicious activity against internet-facing operational technology that caused loss of visibility and, in some cases, forced utilities to use manual operations. Those broader warnings provide relevant defensive context, but they do not prove that the Colorado incidents used the same equipment or attack path.
Was Iran responsible for the Colorado water attacks?
Attribution remains unknown. Colorado said foreign actors were involved but did not identify a country, government or hacking group.
The governor’s office also referenced broader Iranian-backed activity targeting U.S. water systems. That broader threat context must not be converted into incident-specific attribution. The reviewed evidence does not establish that Iranian actors, CyberAv3ngers or another named group carried out the Colorado intrusions.
Which Colorado water utilities were attacked?
The two providers have not been publicly identified in the evidence reviewed by TPS. Officials described them as small privately owned water providers serving fewer than 200 people each.
TPS should not speculate about utility names or infer involvement from geography, ownership type or other cyber incidents. Denver Water separately said it was not affected.
What equipment or PLC models were compromised?
The Colorado incident evidence does not identify the equipment vendor, PLC model, HMI, SCADA platform or remote-access product involved.
This is especially important because separate federal warnings have discussed malicious targeting of internet-facing operational technology and specifically named Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 PLCs in other incidents. That federal product information should not be projected onto the Colorado utilities without incident-specific evidence.
Is this part of the broader U.S. water-sector cyber campaign?
The Colorado incidents occurred during a wider period of malicious targeting of U.S. water and wastewater operational technology. Federal agencies warned in July that utilities in multiple states had reported incidents involving internet-facing PLCs and operational disruption.
However, the reviewed evidence does not technically link the two Colorado incidents to the same actor, infrastructure, exploit path or PLC family described in those federal warnings. The correct current state is therefore: same broader threat environment, specific technical linkage unconfirmed.
What should water utilities check now?
Find internet-exposed OT
Identify PLCs, HMIs, gateways and other operational assets that can be reached directly from the public internet. Current federal guidance urges utilities to remove publicly exposed PLCs and OT where possible.
Validate remote and cellular connections
Review every legitimate external connection into the operational environment, including vendor access, cellular links and remote-maintenance paths. Unknown connectivity should be treated as a security finding.
Review alarms and operator visibility
Confirm that critical alarms, telemetry and remote-access state changes are logged and independently visible so an attacker cannot suppress the only signal operators rely on.
Preserve manual operation
Maintain and test safe manual operating procedures for critical water processes in case remote visibility or automated control is lost during a cyber incident.
Maintain an OT asset inventory
Know which PLCs, HMIs, firmware versions, communications paths and remote-access tools are actually deployed. This makes vendor advisories and incident findings actionable.
Prepare incident-reporting paths
Operators should know how to preserve logs and escalate suspicious OT activity to state authorities and relevant federal cyber or law-enforcement channels.
What is confirmed and what remains unknown?
| Question | Current evidence state |
|---|---|
| Were operational settings changed? | Confirmed by Colorado officials |
| Were alarms and remote access disabled? | Confirmed by Colorado officials |
| Were pumping cycles altered? | Confirmed by Colorado officials |
| Was water quality affected? | Officials say no known impact |
| Was water service interrupted? | Officials say no |
| Were the attackers Iranian? | Unknown |
| Which utilities were affected? | Not publicly identified |
| Which PLC or OT products were used? | Unknown |
| Was this technically linked to the wider U.S. PLC campaign? | Not established |
Colorado water utility cyberattack: direct answers
Did hackers reach operational equipment?
Yes. Colorado says attackers changed equipment settings and altered pumping cycles.
Did hackers contaminate drinking water?
No such impact was reported. Officials said treatment processes and water quality were not affected to their knowledge.
Did customers lose water service?
Colorado said water service and public safety were not affected.
Do officials know who carried out the attack?
No. The state said it could not confirm which foreign actors were responsible.
Were Rockwell MicroLogix PLCs involved?
The reviewed Colorado evidence does not identify the affected equipment. Those PLC models appear in separate federal warnings about other water-sector activity.
Are the Colorado incidents still ongoing?
The reviewed state account says the two providers resolved the incidents quickly. No evidence reviewed by TPS established an ongoing compromise at those two utilities.
Verification method
ThePulseSignal reviewed the Colorado governor-office account carried by current reporting and compared it with FBI, EPA and CISA water-sector OT guidance. TPS kept Colorado-confirmed incident facts separate from broader federal actor and PLC context.
Limitations
The two affected utilities, specific OT products, exact intrusion dates, initial access vector and attacker identity remain undisclosed. Federal warnings about Iranian-linked activity and Rockwell PLCs provide broader threat context but do not establish those facts for the Colorado incidents.