Here’s what happened.
A new cybersecurity breach involving America’s critical infrastructure is raising concerns after foreign actors gained access to the computer systems of two Colorado water utilities and manipulated equipment used to control water operations.
The hackers changed pumping cycles, altered equipment settings and disabled alarms and remote-access functions before local operators were able to regain control.
Colorado officials said the breaches did not contaminate drinking water or interfere with water-treatment processes, and the two affected systems serve only about 400 people.
Even so, the incidents are attracting attention because they show how hackers can move beyond stealing computer files and potentially interfere with physical equipment Americans rely on every day.
The Colorado attacks come amid a broader wave of cyber threats targeting water and wastewater infrastructure across the United States.
Hackers Reached Critical Water Equipment
According to Colorado officials, the attackers were able to manipulate systems connected to the utilities’ physical operations.
That included changing pumping schedules, modifying equipment settings and disabling certain alarms and remote-access capabilities.
Officials said utility workers quickly responded and regained control of the affected systems.
Authorities have not publicly identified the hackers responsible for the Colorado attacks or confirmed whether the incidents are connected to other cyberattacks reported around the country.
The lack of an immediate attribution is not unusual.
Determining who carried out a sophisticated cyberattack can require investigators to analyze computer logs, internet addresses, malware and other technical evidence that attackers may deliberately disguise.
More Than 100 Water Systems Targeted
The Colorado breaches are part of a much larger cybersecurity problem facing America’s water infrastructure.
According to the Environmental Protection Agency, more than 100 drinking-water and wastewater facilities in 12 states have faced major cyberattacks in 2026.
That growing threat has put renewed attention on the computerized equipment used to operate water facilities.
Modern utilities frequently rely on internet-connected technology to monitor and control pumps, valves, water pressure and other important equipment.
These systems can make operations more efficient, but poorly protected internet connections can also create opportunities for hackers.
FBI Issued Warning About Water System Cyberattacks
Federal authorities issued a major warning this summer after malicious cyber actors began targeting operational technology used by water and wastewater utilities.
On July 30, the FBI and EPA said water utilities in at least seven states had reported incidents involving internet-facing programmable logic controllers, or PLCs. Some attacks caused disruptions to water operations.
PLCs are specialized computers used to control industrial machinery and processes.
According to the FBI, attackers remotely accessed some internet-connected devices and changed passwords and network settings, causing utilities to lose monitoring or control functions.
Reported consequences included loss of water pressure and flooding.
The FBI and EPA recommended that utilities remove PLCs from direct exposure to the public internet, use secure gateways and firewalls, strengthen passwords and restrict communications to authorized devices.
Why Operational Technology Is A Major Concern
Traditional cyberattacks often focus on stealing personal information, passwords or financial records.
Attacks involving operational technology can pose a different type of danger because the computer systems are connected to real-world equipment.
At a water utility, those systems may control pumps, valves and pressure systems.
That means unauthorized access could potentially affect the physical operation of a facility rather than simply compromising its data.
The EPA’s inspector general previously identified significant cybersecurity weaknesses across America’s water sector.
A federal assessment covering 1,062 drinking-water systems found that 97 systems serving approximately 26.6 million people had critical or high-risk cybersecurity vulnerabilities as of October 2024.
Iranian-Linked Hackers Have Also Drawn Federal Attention
Foreign cyber activity targeting U.S. infrastructure has become a major concern for federal agencies.
In April 2026, the EPA, FBI, Cybersecurity and Infrastructure Security Agency and National Security Agency issued a joint warning concerning what they described as an ongoing threat from Iranian-affiliated cyber actors.
Federal officials said American organizations, including water and wastewater facilities, had experienced exploitation and in some cases disruptions involving commonly used operational technology.
There has been no public determination that Iranian actors were responsible for the Colorado breaches.
That distinction is important because federal investigators have not publicly attributed those specific incidents to any country or hacking group.
President Donald Trump also previously disputed reports suggesting Iran was responsible for separate cyber activity affecting Minnesota water systems.
Small Water Utilities Can Be Vulnerable
Cybersecurity can be particularly challenging for smaller community water systems.
Major utilities may employ dedicated cybersecurity teams and maintain large technology budgets.
Small and rural providers can operate with fewer workers and fewer resources while still depending on computerized equipment to deliver essential services.
Older technology can also create problems when equipment remains connected to the internet after manufacturers stop providing security updates.
Federal authorities have warned that end-of-life industrial equipment can become an attractive target because known security weaknesses may remain unpatched.
EPA Increasing Cybersecurity Assistance
The federal government has been increasing efforts to strengthen America’s water infrastructure.
The EPA announced in August that it was providing $11.75 million through a drinking-water infrastructure resilience program designed to help utilities prepare for cybersecurity attacks and extreme weather.
The agency has said cyberattacks against critical water infrastructure have increased significantly.
EPA programs are also helping utilities identify cybersecurity vulnerabilities, improve authentication procedures and strengthen access controls.
In February, the agency said it had proactively identified cybersecurity vulnerabilities at 277 water systems during 2025 and worked with those utilities to address the weaknesses.
Colorado is also receiving federal resilience funding.
Denver Water was awarded approximately $1.125 million through the EPA’s infrastructure resilience program.
America’s Water Systems Becoming A Cybersecurity Target
The Colorado breach ended without reported contamination or disruption to water treatment.
That is the good news.
The larger concern is that hackers were apparently able to manipulate equipment associated with essential infrastructure.
Homes, businesses, hospitals, farms, schools and fire departments all depend on reliable water service.
As those systems become increasingly computerized and connected, cybersecurity has become inseparable from the physical security of America’s infrastructure.
Federal agencies are now encouraging utilities to reduce unnecessary internet exposure, strengthen authentication, replace outdated equipment and prepare for situations in which remote computer systems become unavailable.
The FBI’s July warning demonstrates how serious those risks have become: attackers have already caused loss of monitoring capabilities, loss of water pressure and flooding at affected facilities.
For Americans, the Colorado breach is another reminder that today’s national security threats do not always arrive through conventional attacks.
Sometimes they can begin with an exposed computer system connected to a pump, valve or piece of machinery responsible for one of the country’s most basic necessities: clean, reliable water.