- What: Foreign actors breached two small Colorado water systems in August 2026, reaching the programmable logic controllers directly and altering equipment settings, alarms and pump cycles.
- Impact: Colorado says drinking water was not affected, but the intruders held operational control long enough to disable alarms and change pumping. The distance to a real safety event was one operator decision, and that operator did not work for the utility.
- Fix: Get the control systems off the open internet, put monitoring on the OT layer, and alarm on setpoint and alarm-state changes. Copy-paste checks below.
- Who: Any small water, wastewater or utility operator that keeps its controls reachable so a remote handful of staff can run the plant.
A story ran this week about two water utilities in Colorado that foreign hackers walked into last month. The reporting is accurate as far as it goes. What it does not say is that we had already sat across the table from those operators, shown them how someone would get in, and offered to close the gap. They said no. Weeks later, someone else said yes for them.
What happened
In August 2026, two small Colorado water systems serving roughly 400 people between them were breached. The intruders did not touch the water. They touched the controls. They reached the programmable logic controllers directly, the boxes that run the pumps and valves, then turned off alarms, cut remote access, changed pumping cycles, and altered equipment settings. The utilities regained control and alerted the state. Colorado says drinking water quality and treatment were not affected.
Turning off alarms and changing pump cycles is someone learning the plant. The state is right that nobody got sick this time. That is the good news and the whole of it. The distance between what happened and a real safety event was one decision at the keyboard, and the person at the keyboard did not work for the utility.
The part that did not make the report
Roughly two months ago, before any of this, we reached out to water operators in Colorado and walked them through this precise failure mode: control systems reachable from outside, remote access with nothing watching it, and no alarm when the settings change underneath you. The two utilities compromised in August are among the operators we had contacted. We named the exposure. We offered to fix it. They told us their IT team was handling it and they did not need us. That is the sentence that ends most of these conversations, and it is the wrong one: the team that patches the laptops does not watch a PLC, and the tools that guard the office network never see the control network at all.
We are not naming the utilities, and we are not going to. They are small, they are under-resourced, and they made the same call that hundreds of systems like them make every week. The point is not who they are. The point is that the exposure was findable, because we found it, and it was preventable, because we offered to prevent it.
Why this was predictable
None of it required a nation-state. It required a scan. A small utility runs its plant with a skeleton crew and keeps the controls online so a couple of operators can reach them from home. That is reasonable. What makes it dangerous is the rest of the pattern that tends to travel with it: the controllers are reachable from further away than anyone intends, the remote path has no monitoring on it, and nothing raises a hand when a pump schedule or an alarm threshold is quietly rewritten.
An attacker does not need inside knowledge to find that. A scan finds it, which means the defender can find it first, and the fix is rarely exotic. It is knowing what is exposed, watching the control layer the way IT has watched the office network for twenty years, and getting told the moment something changes.
This is a pattern, not a bad week
Colorado is not an outlier. The water sector is being mapped, system by system.
These are not sophisticated campaigns against hardened targets. They are a wide, patient sweep of the softest infrastructure a country has, and the water sector is soft because it was never funded to be anything else.
We keep a passive index of internet-reachable industrial control systems, the same view an adversary builds before choosing a target. As of today it shows close to 400 exposed control systems in Colorado, 40 of them running software with vulnerabilities under active exploitation, including on DNP3 and Modbus, the protocols that run water and power. The two systems in the news are not the last two in Colorado. They are the two that already happened. The rest are neighbors of the utilities that were hit, exposed the same way, right now. We are not publishing which ones, for the obvious reason.
What actually stops it
- Watch the OT, not just the IT. Monitor the control network and the controllers themselves, and alert when settings, alarms, or pump logic change. That is exactly the signal these operators lost the night they were breached.
- Find the exposure before an adversary does. A fixed-scope OT exposure assessment maps what is reachable, from where, and what has nothing watching it. It is the same scan the attacker runs, done for your side first.
- See the radio layer nobody else does. Rural water sites report over control radio that sits in front of the firewall and never appears on the internet. Baseline that spectrum and flag a rogue transmitter, a jammer, or a link that suddenly moved.
- Put it on one timeline. Wired telemetry and the radio layer land in one place, so a command and its effect on the plant line up, and an operator sees the whole picture instead of half of it.
We are not going to publish the how-to for this one. If you run water, wastewater, or any plant with control systems reachable from outside, ask us. We will tell you what of yours is exposed, from where, and what has nothing watching it. That is the same look we offered the utilities that were breached. Email [email protected].
Get the assessment we offered them
If you run water, wastewater, or any plant a small team keeps online from a distance, the OT exposure assessment is fixed in scope and modest against the cost of an incident. We will show you exactly what we would have shown them.
Request an OT assessment