Foreign hackers hit two Colorado water utilities, altered pumps and disabled alarms

By 
, September 19, 2026 
Category:

Foreign cyber actors breached two small Colorado water systems last month, tampering with pumps and disabling safety alarms before operators wrestled back control, the latest in a widening campaign targeting America's most basic infrastructure.

Colorado state officials confirmed Thursday that hackers penetrated the computer networks of two unnamed water utilities, reaching past standard IT defenses and into the operational technology that controls physical equipment. The intruders changed pumping cycles, disabled remote-access capabilities, shut off alarms, and altered equipment settings. The two systems together serve roughly 400 people. Fox News Digital reported that operators eventually regained control, and Gov. Jared Polis' office said the breaches did not affect drinking water quality or treatment processes.

Spokeswoman Eric Maruyama, speaking for Polis' office, framed the incidents as contained:

"These were brief incidents, and the risks were quickly addressed by the providers themselves, who subsequently alerted the state."

Brief or not, the breaches illustrate a pattern that federal agencies have been warning about for months, and that local operators across the country are still failing to stop.

More than 100 water systems hit across 12 states this year alone

The Colorado intrusions did not happen in a vacuum. The EPA, which serves as the federal government's lead risk-management agency for water and wastewater systems, told Fox News Digital it has tracked more than 100 drinking water and wastewater systems targeted across 12 states this year. Since fiscal year 2025, the agency has identified more than 900 vulnerabilities in over 650 water systems and helped eliminate roughly 700 of them at more than 500 utilities.

Those numbers sound large until you consider the scale of the problem. The EPA says it has conducted more than 710 cybersecurity risk assessments and provided direct technical assistance to approximately 15,900 utilities. That is a fraction of the tens of thousands of water systems operating nationwide, many of them small, underfunded, and staffed by operators who were hired to manage pipes and chlorine levels, not fend off nation-state hackers.

The FBI and EPA issued a joint warning in July that malicious cyber actors were targeting internet-connected operational technology at water and wastewater utilities. At that point, utilities in at least seven states had already reported incidents. Federal officials said attackers had remotely accessed internet-facing programmable logic controllers, the industrial devices that open valves, run pumps, and regulate chemical dosing, and tampered with configurations. Some utilities lost monitoring or control capabilities entirely.

Officials urged operators to disconnect those controllers from the open internet and strengthen authentication. The Colorado breaches suggest that advice went unheeded in at least two places.

Minnesota's 30-system summer and the Iran question

Colorado is not the only state dealing with fallout. This summer, cyber activity struck more than 30 community water systems in Minnesota, forcing some utilities onto manual operations and backup procedures. Federal investigators examined whether Iranian actors or hackers affiliated with Iran were responsible.

No public attribution has been made. President Trump, speaking during a Cabinet meeting about the Minnesota attacks, pushed back on the Iran theory. "They blame it on Iran. I don't think so," he said, and instead pointed to Minnesota officials. The source did not specify what actions Trump attributed to those officials.

The FBI declined to comment when Fox News Digital reached out. That silence is itself telling: the bureau has been publicly vocal about the threat in general terms but has offered little transparency about specific incidents, specific attackers, or specific consequences, leaving the public to wonder who is behind the intrusions and whether anyone will be held accountable.

The broader pattern extends well beyond Colorado and Minnesota. Earlier this year, Iran-suspected cyberattacks hit water systems in New Jersey, and federal officials have acknowledged that the threat is national in scope.

Small utilities, big exposure

The Colorado systems serve about 400 people, a tiny customer base by any standard. But that is precisely the point. Small utilities operate on shoestring budgets. They rarely employ dedicated cybersecurity staff. Their equipment often connects to the internet for the convenience of remote monitoring, and the same internet connection that lets an operator check a pump from home lets a foreign hacker do the same from overseas.

When the FBI and EPA described the attack method in July, they were specific: hackers remotely accessed internet-facing programmable logic controllers and changed device configurations. In some cases, the result was a loss of water pressure or flooding, real-world physical consequences triggered by keystrokes thousands of miles away. The Colorado incidents followed the same playbook: altered pumping cycles, disabled alarms, tampered settings.

Water utilities across the country have been scrambling for cybersecurity help as federal resources tighten and the threat grows. The EPA's numbers, 710 risk assessments, 15,900 utilities receiving some form of technical assistance, show effort. They do not show results fast enough to outpace the attackers.

Federal warnings came months ago, breaches kept coming

The timeline matters. The FBI and EPA issued their joint warning in July. The Colorado breaches happened "last month," after that warning had circulated. The Minnesota attacks unfolded over the summer. The multi-state cyberattack campaign federal investigators have been probing did not slow down after the advisory went out, it expanded.

That gap between warning and action is where the real failure sits. Federal agencies can issue all the advisories they want. If a two-person water utility in rural Colorado does not have the money, the expertise, or the mandate to pull its controllers off the public internet, the advisory is a press release, not a defense.

Gov. Polis' office emphasized that drinking water quality was never compromised. That may be true for these two incidents. But hackers who can disable alarms and change pumping cycles have already demonstrated they can reach the equipment that controls treatment. The distance between "changed a pump setting" and "altered a chemical dosage" is not a technological barrier, it is a choice the attacker has not yet made.

The federal warnings triggered by the Minnesota attacks made clear that this is not a theoretical risk. Utilities lost monitoring capabilities. Some experienced flooding and pressure drops. The consequences were physical, not digital.

900 vulnerabilities found, and counting

The EPA's own accounting paints a picture of an infrastructure sector riddled with holes. More than 900 vulnerabilities identified in over 650 water systems since fiscal year 2025. About 700 fixed at more than 500 utilities. That leaves at least 200 known vulnerabilities still open, and those are only the ones the EPA found. The agency has assessed roughly 710 systems out of tens of thousands.

The EPA told Fox News Digital it is working with utilities, states, and federal partners to identify vulnerabilities and strengthen cybersecurity. No verbatim quote was provided. The agency's track record suggests it is aware of the problem. Awareness and prevention are two different things.

Americans who turn on the tap expect clean, safe water. They do not expect that the pump pushing it through the pipe was reprogrammed last week by a foreign government. The federal agencies tasked with protecting this infrastructure have identified the threat, issued the warnings, and counted the vulnerabilities. What they have not done is close the door.

When 400 people in Colorado depend on a water system that a foreign hacker can reach from a laptop, the problem is not a lack of advisories. It is a lack of accountability, and until someone demands it, the next breach is just a matter of time.

About Alan Benson

STAY UPDATED

Subscribe to our newsletter and receive exclusive content directly in your inbox