American Frontline News logo

Foreign hackers infiltrate two Colorado water utilities, alter pumps and disable alarms

Foreign actors broke into the computer systems of two small Colorado water utilities last month, changed pumping cycles, disabled alarms, and tampered with equipment settings before operators managed to wrestle back control. Colorado state officials confirmed the breaches publicly on Thursday, adding the state to a growing and deeply troubling list of American water systems penetrated by hostile cyber actors.

The two utilities serve roughly 400 people combined. Gov. Jared Polis’ office said the intrusions did not affect drinking water quality or treatment processes. But the hackers did not simply poke around office email servers. They reached into operational technology, the industrial controls that govern physical equipment, and manipulated the systems that move water to American homes.

That distinction matters. When a foreign actor can remotely flip a pump cycle or silence an alarm at a water plant, the risk is no longer theoretical. It is mechanical, immediate, and aimed at the infrastructure Americans rely on every day.

A pattern too big to ignore

Colorado is not an isolated case. The EPA says high-profile cyberattacks have targeted more than 100 drinking water and wastewater systems across 12 states this year alone. This summer, hackers hit computerized controls at more than 30 community water systems in Minnesota, forcing some utilities onto manual operations and backup procedures. Federal investigators have examined whether Iranian actors were behind the Minnesota attacks, though officials had not publicly attributed the activity at the time of the Colorado announcement.

President Trump, speaking during a Cabinet meeting about the Minnesota incidents, pushed back on the Iran theory. “They blame it on Iran. I don’t think so,” he said, instead pointing to Minnesota officials.

The Colorado hackers have been described only as “foreign actors.” No specific nation-state attribution has been made public. The FBI declined to comment when Fox News Digital reached out about the Colorado breaches.

That silence is becoming a pattern of its own. The federal government has previously charged individuals linked to Russian-backed cyberattacks on U.S. water systems, and the FBI has pursued state-linked hacking networks from multiple adversary nations. Yet when new incidents surface, the public often waits weeks or months for answers, if answers come at all.

How the hackers got in

The method tracks with what federal authorities have warned about for months. In July, the FBI and EPA issued a joint warning that malicious cyber actors were targeting internet-connected operational technology at water and wastewater utilities. At that point, utilities in at least seven states had already reported incidents, some of which degraded water operations.

The attackers remotely accessed internet-facing programmable logic controllers, the small industrial computers that tell pumps, valves, and chemical dosing systems what to do. Once inside, they tampered with device configurations. In some cases, utilities lost monitoring or control capabilities entirely.

Federal officials have urged operators to pull programmable logic controllers off the open internet and strengthen authentication and access controls. The advice is sound. The question is why so many small utilities still have critical equipment exposed to anyone with an internet connection and enough skill to exploit it.

The vulnerability is staggering in scope. Since fiscal year 2025, the EPA has identified more than 900 vulnerabilities in over 650 water systems. The agency says it has helped eliminate about 700 of those vulnerabilities at more than 500 utilities, conducted more than 710 cybersecurity risk assessments, and provided direct technical assistance to approximately 15,900 utilities.

Small systems, big risks

The two Colorado utilities serve a combined population of about 400. That is a tiny footprint, the kind of system that runs on a shoestring budget with a handful of operators, not a dedicated cybersecurity team. These are exactly the targets hostile actors look for: under-resourced, under-monitored, and connected to the internet because remote access is cheaper than a full-time on-site staff.

Eric Maruyama, a spokeswoman for Gov. Polis, framed the incidents carefully:

“These were brief incidents, and the risks were quickly addressed by the providers themselves, who subsequently alerted the state.”

“Brief” and “quickly addressed” are reassuring words. But “brief” still means foreign actors controlled American water infrastructure long enough to change how pumps operated and to disable the alarms designed to catch exactly that kind of tampering. The operators caught it. Next time, at a different utility, they might not.

Colorado already knows what happens when small communities lose access to clean water. The state declared one small town effectively abandoned after every elected official resigned and residents were left without reliable water service. The cause there was governance failure, not hacking, but the result for the people who depend on the system is the same: a public utility that cannot be trusted to function.

The federal response so far

The EPA told Fox News Digital it is working with utilities, states, and federal partners to identify vulnerabilities and strengthen cybersecurity. The numbers the agency cites, hundreds of assessments, thousands of utilities assisted, suggest activity. Whether that activity matches the scale of the threat is another question.

More than 100 systems hit across 12 states in a single year. More than 900 vulnerabilities identified. And still, foreign actors are reaching into operational controls at small-town water plants and flipping switches.

The broader pattern of cyberattacks on American public infrastructure extends well beyond water. A cyberattack forced a California city to shut down its network, knocking out 911 systems, the kind of cascading failure that puts lives at immediate risk when emergency communications go dark.

And the threat actors are not freelancers working out of basements. The FBI has dismantled Chinese state-linked hacking networks that breached U.S. government agencies. State-backed cyber operations from China, Russia, and Iran have all been documented targeting American critical infrastructure in recent years. When the EPA and FBI issued their July warning, they were not speculating about a future risk. They were describing attacks already underway.

What remains unanswered

Key questions remain open. Who are the “foreign actors” behind the Colorado breaches? Are the two incidents connected to each other, or to the wider national wave? Did the Colorado utilities notify federal authorities in addition to the state? What specific equipment settings were altered beyond pumping cycles, and what were the full operational effects?

The names and locations of the two utilities have not been released. The FBI’s refusal to comment leaves the public guessing about whether an investigation is active, whether attribution is forthcoming, or whether these incidents will simply join a growing pile of unresolved cyber intrusions against American infrastructure.

For the roughly 400 residents served by these two systems, the reassurances from the governor’s office may provide some comfort. The water kept flowing. The treatment process was not compromised. Operators caught the problem and fixed it.

But the fact that foreign actors reached the controls at all, and that the alarms meant to detect exactly this kind of intrusion were disabled by the intruders themselves, should concern every American who turns on a faucet and assumes the system behind it is secure.

When hostile nations can remotely manipulate the pumps that deliver drinking water to American families, “brief” is not the same as “safe.” It just means we got lucky this time.

AMERICAN FRONTLINE ALERTS

Never Miss a Story.

By signing up, you agree to receive newsletters and promotional content from American Frontline News and selected publications in the American Digest Media Network, operated with Patriot Mom Digest LLC, and you accept our Terms of Use and Privacy Policy. You may unsubscribe at any time.

AMERICAN FRONTLINE ALERTS

Never Miss a Story.

Breaking stories and the coverage the other guys won't touch — straight to your inbox.

By signing up, you agree to receive newsletters and promotional content from American Frontline News and selected publications in the American Digest Media Network, operated with Patriot Mom Digest LLC, and you accept our Terms of Use and Privacy Policy. You may unsubscribe at any time.