
Two small Colorado water utilities, each serving fewer than 200 people, were briefly hacked by foreign actors last month, according to Governor Jared Polis's office. State officials say the intruders altered pumping cycles, disabled remote access and alarms, and changed equipment settings — but treatment processes and water quality were never affected at either provider.
The breaches were confirmed by state officials and first reported by The Denver Post. According to that report, the two unnamed utilities alerted the state after discovering the intrusions in late August and moved quickly to address the risks. Polis's office said it could not confirm which foreign actors were involved, although an Iran-backed hacking group has been linked to similar attacks elsewhere in the country. The governor's office declined to identify the utilities, and the Colorado Rural Water Association did not respond to requests for comment, the newspaper reported.
A Familiar Pattern of Small-System Vulnerability
The Colorado incidents fit a pattern federal officials have been flagging for months. The FBI and several federal agencies warned in April that Iranian-affiliated threats were seeking to cause disruptive effects in the United States by targeting water and energy systems, according to the Denver Post's account of the timeline. The Cybersecurity and Infrastructure Security Agency has said the Iranian-backed group has ongoing efforts to access drinking water and wastewater systems nationwide. Separate incidents reported in July affected utilities in at least seven states, though the available federal notices do not establish that those events or the suspected Iranian activity were connected to the Colorado breaches.
FBI spokesperson Vikki Migoya told the paper that the bureau typically does not comment on investigative work, leaving the question of attribution for the Colorado breaches unresolved. Former intelligence officials and cybersecurity experts told the New York Times in August that hackers were likely acting opportunistically rather than deliberately targeting specific local governments — a distinction state officials in Colorado have echoed as they weigh how to respond.
Why Small Utilities Stay So Exposed
The vulnerability isn't unique to Colorado. An Environmental Protection Agency enforcement alert found that more than 70% of inspected community drinking water systems nationwide were violating basic Safe Drinking Water Act cybersecurity requirements, such as failing to change default passwords or using shared logins, according to CyberScoop. Part of the problem is structural: under Section 1433 of the Safe Drinking Water Act, mandatory risk-and-resilience assessments only apply to systems serving more than 3,300 people, according to the Congressional Research Service, leaving small utilities — which make up more than 80% of the country's community water systems — exempt from federal cyber mandates.
Federal oversight has also faced legal setbacks. The EPA rescinded an interpretive memorandum in October 2023 that would have required state regulators to audit water systems' operational technology cybersecurity during routine sanitary surveys, after Missouri, Arkansas, Iowa and water industry groups challenged the measure in the 8th U.S. Circuit Court of Appeals, per CyberScoop. That legal fight left cybersecurity monitoring largely voluntary for state drinking water programs. The precedent for what can go wrong dates back further: separate reporting has described an IRGC-backed attack on industrial water-treatment controls.
Colorado's Response and Broader Cyber Guidance
The Colorado Department of Public Health and Environment regulates more than 2,000 active public water systems statewide, according to the department. The agency's role in responding to water-system security incidents is not specified in the cited sources.
State officials say they are monitoring national cybersecurity trends and are communicating directly with Colorado water providers, encouraging them to double-check security measures and make necessary updates. Facilities relying on vulnerable, internet-connected operational systems remain at particular risk, and federal cybersecurity officials have urged utilities nationwide to unplug internet-connected controllers where possible. Sarah Tuneberg reported to state lawmakers that Colorado has seen an increase in external international actors attempting to attack state infrastructure, the Denver Post noted.
Polis's office has separately distributed new cybersecurity guidance to state agencies requiring live video and in-person identity checks for job-candidate interviews, aimed at reducing the risk of foreign actors accessing state systems. That guidance follows concerns that North Korean threat actors may have attempted to gain employment information and access Colorado systems, though the Denver Post's reporting does not confirm any successful intrusion tied to that effort.
Part of a Wider National Campaign
The Colorado breaches arrived amid a broader wave of attacks on water infrastructure controls. In a separate public service announcement, the FBI and EPA said that since July 27, 2026, utilities in at least seven states had reported incidents involving internet-facing Rockwell Automation/Allen-Bradley programmable logic controllers, with some activity degrading water operations. The agencies did not establish that those reports were connected to Colorado's breaches; the campaign was also described in Industrial Cyber. An EPA Inspector General evaluation of 1,062 large drinking water systems serving at least 50,000 residents identified 97 systems with critical or high-risk cybersecurity vulnerabilities, affecting roughly 26.6 million people — a reminder that exposure spans both major metro systems and rural providers like the two in Colorado.
Municipal water operational technology remains a cybersecurity concern. In response to the mounting threat, a six-month pilot for drinking-water systems was launched in 2026 after already being under development.
What federal data and support show
According to the EPA Office of Inspector General, a passive assessment of 1,062 drinking water systems serving 50,000 people or more found 97 with critical or high-risk cybersecurity vulnerabilities affecting approximately 26.6 million users. The assessment covered systems serving more than 193 million people, and the findings were based on scan results from Oct. 8, 2024; they provide a national baseline but are not directly comparable to Colorado's two utilities serving fewer than 200 people.
For smaller communities, the EPA said on July 24, 2026, that it had announced $30.7 million in grants for three organizations to provide training and technical assistance to small and rural communities. The funding offers a concrete support option beyond voluntary warnings, while the Colorado cases underscore why those systems remain part of the national cybersecurity picture.









