Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology
UNDERREPORTED

Foreign hackers infiltrate Colorado water utilities, alter pumps and alarms but avoid contamination

Foreign actors breached two Colorado water utilities last month, changing pump cycles and disabling alarms, while drinking water quality stayed safe.

State officials disclosed that foreign actors compromised the computer networks of two Colorado water utilities in the previous month, altering pump cycles, disabling alarms and modifying equipment settings before operators restored control. The governor’s office confirmed that drinking water quality and treatment processes were not affected. These brief incidents illustrate how cyber intruders can move beyond traditional IT systems to manipulate operational technology such as pumps and valves.

Colorado joins more than 100 drinking water and wastewater facilities across 12 states that have experienced similar attacks this year, according to the EPA. Federal agencies have warned that internet-connected programmable logic controllers are vulnerable, urging utilities to remove them from direct internet exposure and improve authentication. The events underscore ongoing cybersecurity challenges for small, rural utilities with limited resources.

Why it matters

The attacks reveal how vulnerable water infrastructure is to cyber threats, risking public safety and service reliability.

In this story

foreign hackersColorado water utilitiesoperational technologycyberattackpumping cyclesPLC vulnerabilitiesdrinking water safetyinternet-connected control systemsEPAFBI
Get the beta ↗