Hackers Breach Colorado Water Utilities, Alter OT Operations

Foreign Hackers Breach Two Colorado Water Utilities, Manipulate Systems

HIGH
September 19, 2026
October 3, 2026
5m read
Industrial Control SystemsCyberattackThreat Actor

Full Report(when first published)

Executive Summary

On September 18, 2026, the office of Colorado Governor Jared Polis confirmed that two small, privately-owned water utilities in the state were breached by foreign hackers in late August. The attackers gained access to the utilities' operational technology (OT) networks and manipulated industrial control systems (ICS). Specific actions included altering equipment settings, changing pumping cycles, and disabling alarms. While officials stated that water service and quality were not impacted, the incidents represent a direct compromise of critical infrastructure and highlight a growing trend of attacks against the U.S. water and wastewater sector. This event follows a joint alert from the FBI and CISA regarding a nationwide increase in such attacks.


Threat Overview

The attacks targeted two small utilities, each serving fewer than 200 people, indicating that even the smallest infrastructure providers are in scope for threat actors. The attackers' goal appears to have been disruption and demonstrating capability rather than causing immediate, widespread harm. The governor's office acknowledged awareness of ongoing campaigns by Iranian-backed groups targeting U.S. water systems, though they did not formally attribute these specific incidents.

This pattern of attack is consistent with a nationwide campaign. The FBI and CISA noted that similar intrusions have occurred in at least seven states in recent weeks, including a large-scale, coordinated attack that hit over 30 facilities in Minnesota in late July 2026. The common thread is the targeting of internet-exposed ICS/SCADA systems that are often secured with weak, default, or easily guessable credentials.

Technical Analysis

The threat actors were able to directly interact with the OT environment. Their actions fall under several MITRE ATT&CK for ICS techniques:

  • Altering Pumping Cycles: This is a form of T0831 - Manipulation of Control, where attackers modify the state of physical control systems to cause a disruptive effect.
  • Disabling Alarms: This corresponds to T0829 - Manipulation of View or T0828 - Loss of View, as it blinds operators to hazardous conditions or unauthorized changes.
  • Changing Equipment Settings: This is another example of manipulating control logic to alter the physical process.

The initial access vector is consistently reported as the exploitation of internet-facing control systems, likely through brute-forcing weak credentials or using default passwords, a form of T0886 - Remote Services.

Impact Assessment

While these specific incidents did not result in contaminated water or service disruption, the potential impact is severe. Successful manipulation of water treatment and distribution systems could lead to public health crises, environmental damage, and loss of public trust in essential services. The psychological impact on operators and the community is also significant. These attacks serve as a stark warning that even small-scale intrusions can have strategic consequences by demonstrating the vulnerability of a nation's critical infrastructure. The low-sophistication, high-impact nature of these attacks makes them a potent tool for nation-state actors seeking to cause disruption.

IOCs — Directly from Articles

No specific Indicators of Compromise were provided in the source articles.

Cyber Observables — Hunting Hints

Security teams at water utilities should hunt for the following patterns:

Type
network_traffic_pattern
Value
Inbound RDP/VNC/Telnet
Description
Monitor for any inbound connections using remote access protocols to the OT network from the internet. This should be a high-fidelity alert.
Type
log_source
Value
HMI/SCADA Audit Logs
Description
Look for logins from unusual geolocations, multiple failed login attempts followed by a success, or changes made outside of normal operator shifts.
Type
other
Value
PLC Logic Mismatch
Description
If possible, periodically compare the running logic on a Programmable Logic Controller (PLC) with a known-good backup. Any unauthorized change is a critical indicator.
Type
other
Value
Anomalous Setpoints
Description
Monitor for changes to critical operational setpoints (e.g., chlorine levels, pump speeds, valve positions) that fall outside of normal operational parameters.

Detection & Response

  • Detection: Deploy OT-aware network security monitoring solutions that can parse ICS protocols and identify unauthorized commands or setpoint changes. Establish a baseline of normal network behavior and operator actions and alert on deviations. This aligns with D3FEND Network Traffic Analysis (D3-NTA).
  • Response: In the event of a suspected compromise, the first priority is to ensure public safety. This may involve immediately switching to manual operations to override malicious commands. Isolate the affected OT network from the IT network and the internet. Preserve logs and system images for forensic analysis.

Mitigation

CISA and the FBI recommend the following critical mitigation steps for all water and wastewater systems:

  1. Eliminate Internet Exposure: Do not expose any ICS/SCADA systems directly to the internet. If remote access is necessary, it must be behind a firewall and require multi-factor authentication (MFA) via a VPN. (M0916 - Remote Access).
  2. Strong Password Policies: Change all default passwords on ICS hardware and software. Implement and enforce a strong password policy for all accounts. (M0938 - User Account Management).
  3. Network Segmentation: Implement robust network segmentation between IT and OT networks. All communication between the two should be strictly controlled and monitored through a DMZ. (M0930 - Network Segmentation).
  4. Create a Cybersecurity Response Plan: Develop and practice an incident response plan that specifically addresses OT system compromise and includes procedures for switching to manual operations.

Timeline of Events

1
July 31, 2026
A coordinated attack hits over 30 water and wastewater facilities in Minnesota.
2
August 31, 2026
Foreign hackers breach two water utilities in Colorado (approximate date).
3
September 18, 2026
The office of Colorado Governor Jared Polis confirms the breaches.
4
September 19, 2026
This article was published

Article Updates

October 3, 2026

Widespread U.S. water utility attacks intensify, with phishing identified as primary initial access. State-sponsored actors shift focus to disruptive actions, increasing overall threat.

MITRE ATT&CK Mitigations

Properly segmenting OT networks from IT networks and the internet is the most critical defense against these types of attacks.

Securing all remote access with strong authentication (MFA) and VPNs prevents attackers from easily accessing internet-exposed systems.

Enforcing strong, unique passwords and eliminating default credentials for all HMI, PLC, and SCADA components.

Having a well-defined and practiced incident response plan enables operators to react quickly and safely to a compromise.

Timeline of Events

1
July 31, 2026

A coordinated attack hits over 30 water and wastewater facilities in Minnesota.

2
August 31, 2026

Foreign hackers breach two water utilities in Colorado (approximate date).

3
September 18, 2026

The office of Colorado Governor Jared Polis confirms the breaches.

Sources & References(when first published)

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

ICSSCADAOT SecurityCritical InfrastructureWater UtilityCyberattack

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.