
Reports indicate that in late August, hackers attempted cyberattacks targeting the Operational Technology (OT) systems of two small private water utilities in Colorado, United States. Although the incidents involved attempts to interfere with operational systems, the utilities were able to respond and contain the risk quickly. As a result, there was no impact on drinking water quality, service availability, or public safety. However, the incidents highlight the importance of cybersecurity for critical infrastructure, particularly at smaller organizations that often face limitations in security personnel and resources.
According to reports, the attackers altered device configurations, blocked remote access, disabled alarm systems, and changed pump operating cycles. Information from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) indicates that previous attacks against water systems have often involved industrial control devices, or Programmable Logic Controllers (PLCs), that were directly exposed to the internet through cellular modems without firewall protection. This configuration can allow attackers to remotely access devices, change IP addresses and passwords, and interfere with operations. Although U.S. authorities have stated that foreign-backed threat actors have continued targeting the country’s water infrastructure, any direct connection between such groups and the incidents in Colorado remains under investigation.
To reduce the risk of similar threats, OT administrators and critical infrastructure operators should review whether their PLCs and industrial systems are directly exposed to the public internet. Risk reduction does not necessarily require organizations to eliminate remote access entirely, but unnecessary internet-facing connections should be disabled, while essential remote access channels should be protected with strong security controls. Organizations should also conduct regular cybersecurity risk assessments to identify and remediate weaknesses that could allow unauthorized access to critical control systems.
