On September 18, 2026, the office of Colorado Governor Jared Polis confirmed that two small, privately-owned water utilities in the state were breached by foreign hackers in late August. The attackers gained access to the utilities' operational technology (OT) networks and manipulated industrial control systems (ICS). Specific actions included altering equipment settings, changing pumping cycles, and disabling alarms. While officials stated that water service and quality were not impacted, the incidents represent a direct compromise of critical infrastructure and highlight a growing trend of attacks against the U.S. water and wastewater sector. This event follows a joint alert from the FBI and CISA regarding a nationwide increase in such attacks.
The attacks targeted two small utilities, each serving fewer than 200 people, indicating that even the smallest infrastructure providers are in scope for threat actors. The attackers' goal appears to have been disruption and demonstrating capability rather than causing immediate, widespread harm. The governor's office acknowledged awareness of ongoing campaigns by Iranian-backed groups targeting U.S. water systems, though they did not formally attribute these specific incidents.
This pattern of attack is consistent with a nationwide campaign. The FBI and CISA noted that similar intrusions have occurred in at least seven states in recent weeks, including a large-scale, coordinated attack that hit over 30 facilities in Minnesota in late July 2026. The common thread is the targeting of internet-exposed ICS/SCADA systems that are often secured with weak, default, or easily guessable credentials.
The threat actors were able to directly interact with the OT environment. Their actions fall under several MITRE ATT&CK for ICS techniques:
T0831 - Manipulation of Control, where attackers modify the state of physical control systems to cause a disruptive effect.T0829 - Manipulation of View or T0828 - Loss of View, as it blinds operators to hazardous conditions or unauthorized changes.The initial access vector is consistently reported as the exploitation of internet-facing control systems, likely through brute-forcing weak credentials or using default passwords, a form of T0886 - Remote Services.
While these specific incidents did not result in contaminated water or service disruption, the potential impact is severe. Successful manipulation of water treatment and distribution systems could lead to public health crises, environmental damage, and loss of public trust in essential services. The psychological impact on operators and the community is also significant. These attacks serve as a stark warning that even small-scale intrusions can have strategic consequences by demonstrating the vulnerability of a nation's critical infrastructure. The low-sophistication, high-impact nature of these attacks makes them a potent tool for nation-state actors seeking to cause disruption.
No specific Indicators of Compromise were provided in the source articles.
Security teams at water utilities should hunt for the following patterns:
Inbound RDP/VNC/TelnetHMI/SCADA Audit LogsPLC Logic MismatchAnomalous SetpointsCISA and the FBI recommend the following critical mitigation steps for all water and wastewater systems:
M0916 - Remote Access).M0938 - User Account Management).M0930 - Network Segmentation).Widespread U.S. water utility attacks intensify, with phishing identified as primary initial access. State-sponsored actors shift focus to disruptive actions, increasing overall threat.
Properly segmenting OT networks from IT networks and the internet is the most critical defense against these types of attacks.
Securing all remote access with strong authentication (MFA) and VPNs prevents attackers from easily accessing internet-exposed systems.
Enforcing strong, unique passwords and eliminating default credentials for all HMI, PLC, and SCADA components.
Having a well-defined and practiced incident response plan enables operators to react quickly and safely to a compromise.
A coordinated attack hits over 30 water and wastewater facilities in Minnesota.
Foreign hackers breach two water utilities in Colorado (approximate date).
The office of Colorado Governor Jared Polis confirms the breaches.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.