Foreign hackers slipped into two Colorado water utility systems and managed to meddle with controls tied to pumping, alarms, and equipment settings before the utilities wrestled back control. Officials say the attacks did not contaminate drinking water, but they exposed just how quickly a small breach can turn into a real-world scare when the target is critical infrastructure.
The incidents landed in the middle of a much bigger problem. Federal officials say cyberattacks have hit more than 100 drinking water and wastewater systems across 12 states this year, a number that keeps the threat from sounding abstract and pushes it straight into daily life.
Colorado Gov. Jared Polis’ office said the two affected systems serve roughly 400 people, which makes the scale feel small on paper and still serious in practice. The intrusions were brief, but they were enough to show that attackers do not need to wreck a plant to create confusion, stress, and expensive cleanup.
State officials have not pinned the breaches on any specific group, and they have not said whether the Colorado incidents are tied to the wider wave of attacks reported elsewhere. What they do know is straightforward: hackers altered equipment settings, shut off remote access and alarms, and changed pumping cycles before the problems were caught.
That matters because these were not ordinary office networks getting poked at from a distance. Water plants rely on operational technology to manage pumps, valves, pressure, and other physical systems, so a digital intrusion can reach deep into machinery that keeps water flowing in the real world.
The broader federal warning came earlier this summer, when the FBI and the EPA said malicious actors were targeting internet-connected operational technology at water and wastewater utilities. Officials said some of those attacks involved remote access to programmable logic controllers, better known as PLCs, with some utilities losing monitoring or control functions along the way.
Those effects sound technical, but the consequences are not. Loss of water pressure, flooded equipment, and disrupted operations can hit communities fast, especially in places where there are not many backup people or systems ready to step in at a moment’s notice.
Colorado’s case also fits a pattern that has already played out in other states. Minnesota saw cyber activity affecting more than 30 community water systems this summer, adding to the sense that local utilities are being tested one after another instead of facing isolated one-off events.
Small and rural systems are often the most exposed because they tend to run lean. They may depend on internet-connected tools to monitor operations from afar, but those same tools can become a doorway if security is weak or equipment is left too open to the internet.
The EPA says it has been working with utilities, states, and federal partners to tighten those gaps. Since fiscal year 2025, the agency says it has identified more than 900 vulnerabilities in over 650 water systems and helped eliminate about 700 of them at more than 500 utilities.
That cleanup effort has gone hand in hand with more hands-on support. The agency says it has carried out more than 710 cybersecurity risk assessments and given direct technical assistance to around 15,900 utilities, a sign that the problem is spreading far beyond a few headlines and into the everyday plumbing of public life.
The latest Colorado breach keeps the focus on a hard truth: water systems now sit in the crosshairs of hackers who understand that pressure, alarms, and remote controls can be just as powerful as stolen files. And when that kind of access lands in the wrong hands, the danger is not just digital, it is sitting at the tap.

1 Comment
Can do this nationwide Must remedy security now 24/7