> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Foreign Hackers Target Two Colorado Water Utilities

[SOURCE] Security Affairs [AUTHOR: Pierluigi Paganini] [DATE: 21/09/2026 18:09] [LANGUAGE: EN]
Hackers targeted two Colorado water utilities, changing OT settings and disabling alarms, but causing no impact on water services or safety. Foreign hackers targeted the operational technology (OT) systems of two small private water utilities in Colorado in late August, apparently trying to disrupt operations. Local authorities haven’t identified the affected utilities or the attackers. Attackers reportedly changed equipment settings, disabled remote access and alarms, and modified pumping cycles. The incidents were brief and did not affect water services or public safety. The utilities serve fewer than 200 people, and few technical details are available. The Colorado governor added the attack was carried out by ‘foreign actors’. “The intrusions did not affect drinking water quality or treatment processes, according to Colorado Gov. Jared Polis’ office. But the incidents add Colorado to a widening series of breaches in U.S. water and wastewater infrastructure.” reported Fox News. “These two incidents consisted of individuals changing equipment settings, disabling remote access and alarms, and altering pumping cycles,” Polis spokeswoman Ally Sullivan said in a statement. “These were brief incidents, and the risks were quickly addressed by the providers themselves, who subsequently alerted the state.” “We cannot confirm what foreign actors may have been involved, but we are aware of ongoing efforts across the nation by an Iranian-backed group to access drinking water and wastewater systems, as per the Cybersecurity and Infrastructure Security Agency,” Sullivan wrote in a separate statement. Despite references to Iran-linked attacks, there is no confirmation that the two Colorado utilities were part of the same campaign that targeted water facilities in at least a dozen US states in July. Federal authorities have not published a complete list of affected utilities. However, confirmed targets include facilities in Minnesota, Michigan, Alabama, Georgia, New Jersey, South Dakota,and Wisconsin. The available evidence does not currently establish a direct link between those attacks and the Colorado incidents. The recent attacks have renewed concerns about cybersecurity weaknesses in U.S. water infrastructure, especially at small and rural utilities that often have limited security staff and resources. In August, CISA urged water utilities to find and secure internet-exposed PLCs after July attacks showed how easily exposed industrial systems can be compromised. Over 100 internet-exposed systems in the US water and wastewater sector got hit by cyberattacks in July 2026, and CISA’s response wasn’t just an incident report, it was a how-to guide for making sure it doesn’t happen to you next. The agency’s exposure reduction guidance, published August 21, walks through exactly how organizations can find their own internet-facing weak points before an attacker does. The pattern behind the July attacks was surprisingly simple. Most of the affected systems were programmable logic controllers (PLCs), small industrial computers that control pumps and valves. Many connected directly to cellular modems and had no firewall or gateway between them and the internet. CISA warns that this type of setup can expose PLCs to serious security risks. “Directly connecting PLCs to the internet through cellular modems can create significant security risks. However, internet exposure reduction does not mean disabling necessary remote access; organizations should remove remote access when it is unnecessary and secure it when it is necessary.” states CISA. Hackers remotely accessed exposed PLCs, changed device IP addresses and passwords, and in some cases disabled shutdown processes and alarms, creating what CISA called unsafe conditions without notifying the operators running the actual equipment. Iran is the suspected actor behind much of this activity, likely tied to the ongoing war involving the US and Israel, though officials have stopped short of a formal attribution. Since fiscal year 2025, the EPA has identified more than 900 vulnerabilities across over 650 water systems and helped address about 700 of them at more than 500 utilities. The agency has also carried out more than 710 cybersecurity risk assessments and provided technical support to around 15,900 utilities. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, water utilities)
[messages.read_original_source] →