Foreign hackers alter water controls at two Colorado utilities

Foreign hackers alter water controls at two Colorado utilities. Foreign hackers changed operational settings and alarms at two small Colorado water utilities in late August.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 22nd, 2026.

Foreign hackers changed operational settings and alarms at two small Colorado water utilities in late August. They altered pumping cycles and disabled remote access and alarms, but the providers responded quickly. Water service and public safety weren’t affected. Each utility serves fewer than 200 people, and officials haven’t identified the attackers or confirmed that these incidents were connected to other campaigns.

The absence of an outage doesn’t make this a minor event. Small utilities still operate systems where a cyber intrusion can affect physical processes. Internet-exposed industrial controls and direct cellular connections can create a short route to pumps and alarms. Limited staffing and a small customer base don’t reduce the need for basic safeguards around operational technology.

Defenders should identify exposed controllers, remove remote access that isn’t necessary, and secure and monitor any access that must remain. The practical priority is to inventory every internet-accessible controller and place required remote access behind monitored, strongly authenticated gateways. The larger lesson is simple: basic exposure can become physical interference without an attacker needing sophisticated malware.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Foreign hackers alter water controls at two Colorado utilities
Broadcast by