As reported by SecurityAffairs, foreign hackers compromised the operational technology systems of two small private water utilities in Colorado in late August, altering equipment settings, disabling alarms, and modifying pumping cycles. Governor Jared Polis's office attributed the intrusions to 'foreign actors' and acknowledged awareness of Iran-linked campaigns targeting water infrastructure across multiple states.

Threat Intelligence: As reported by SecurityAffairs, foreign hackers compromised the operational technology systems of two small private water utilities in Colorado in late August, altering equipment settings, disabling alarms, and modifying pumping cycles.

The Target Profile Tells the Story

These utilities serve fewer than 200 people combined. That detail is not incidental — it is the core of the threat model. Small and rural water systems across the United States operate with skeletal staff, legacy programmable logic controllers (PLCs), and internet-facing remote access that was never designed for the current threat environment. When CISA disclosed that over 100 internet-exposed systems in the water and wastewater sector were hit in July 2026 alone, the agency was describing the same structural weakness: operators need remote access for efficiency, but the security posture supporting that access ranges from inadequate to nonexistent.

The attackers did not need sophisticated tradecraft. They needed exposed interfaces and default credentials — the same combination that has plagued ICS security for a decade.

Attribution: Probable but Unconfirmed

The governor's office referenced Iranian-backed activity based on CISA reporting, but stopped short of confirming these specific incidents link to the broader July campaign that hit utilities in Minnesota, Michigan, Alabama, Georgia, New Jersey, South Dakota, and Wisconsin. This ambiguity matters. Iran-aligned groups — most notably CyberAv3ngers, associated with the Islamic Revolutionary Guard Corps (IRGC) — have historically targeted Israeli-made Unitronics PLCs, but the operational footprint of these campaigns suggests opportunistic scanning rather than curated targeting. Any exposed system, regardless of vendor, is a potential victim.

Why the Impact Was Limited — and Why That Won't Last

The Colorado incidents were contained because the utilities detected anomalies quickly and self-reported. Altering pumping cycles and disabling alarms is disruptive but not inherently dangerous in a system serving 200 people with manual oversight capacity. Scale that same attack to a midsize municipal utility serving 50,000 residents with fully automated treatment, and the calculus changes dramatically. The industry got lucky. Again.

What Defenders Should Focus On

CISA's August guidance urged utilities to locate and secure internet-exposed PLCs. That is necessary but insufficient. The systemic issue is that water utilities — particularly small ones — lack the security operations capacity to maintain visibility over their OT environments. Detection in these incidents came from operational staff noticing something wrong, not from SOC analytics or EDR alerts. That model does not scale to the threat.

Shield53 Recommendations

  • Eliminate unnecessary internet exposure: Conduct continuous external attack surface discovery (Shodan, Censys, GreyNoise) against your IP ranges. Any PLC, HMI, or engineering workstation reachable from the internet without a VPN and MFA is a critical exposure.
  • Enforce network segmentation: OT networks must be isolated from IT and internet. Implement ICS-aware firewalls (purdue model architecture) and deny-all default policies between zones.
  • Harden remote access: Replace any plaintext or unauthenticated remote access with zero-trust network access (ZTNA) or vendor-approved secure gateways. Disable remote access entirely where manual local operation is feasible.
  • Change default credentials: Audit every PLC, RTU, and HMI for vendor-default passwords. This remains the single most exploited weakness in water sector intrusions.
  • Enable OT-aware monitoring: Deploy passive OT network monitoring (e.g., Claroty, Dragos, Nozomi) to detect configuration changes, unauthorized login attempts, and protocol anomalies. These systems identified the July campaign activity before impact in several cases.
  • Participate in information sharing: Join the WaterISAC and integrate CISA cyber hygiene scan results. Small utilities should leverage free CISA services including Cyber Hygiene scans and vulnerability scanning.
  • Develop and test OT incident response plans: The Colorado utilities detected the intrusion because operators noticed changes manually. Formalize that detection into playbooks with defined escalation, containment, and reporting procedures.

The pattern is now clear: nation-state actors are conducting reconnaissance and disruption operations against U.S. water infrastructure at scale. The July campaign, the Colorado incidents, and the earlier attacks on Unitronics devices in Pennsylvania are not isolated events — they are iterations of a sustained campaign testing American critical infrastructure resilience. Utilities that have not yet been targeted should assume they are on a list and act accordingly.