Foreign actors breached the operational technology and industrial control systems of two unnamed, privately owned Colorado water utilities in late August. Each utility serves fewer than 200 people. The intruders changed equipment settings, disabled remote access and alarms, and altered pumping cycles; disruption was brief, with no reported interruption to water service or impact on public safety.
Colorado officials did not identify the perpetrators, the affected utilities, or the initial access method. They said they were aware of a broader Iranian-backed campaign targeting U.S. drinking-water and wastewater systems but did not attribute the Colorado intrusions to it. The incidents follow July attacks against roughly 100 internet-exposed water systems across at least seven states, underscoring the exposure of small utilities' internet-accessible OT environments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Foreign actors targeted the operational technology and industrial-control systems of two unnamed privately owned Colorado water utilities, each serving fewer than 200 people. The intruders changed equipment settings, disabled remote access and alarms, and altered pumping cycles; disruption was brief, with no water-service interruption or public-safety impact reported.
Cyberattacks targeted approximately 100 internet-exposed U.S. water systems. Confirmed victims were located in Minnesota, Michigan, Georgia, South Dakota, New Jersey, Wisconsin, and Alabama; federal authorities had not released a complete victim list.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.