Foreign Actors Target U.S. Water Utilities in Cyberattacks
Foreign actors gained unauthorized access to Colorado water utilities as part of a broader campaign targeting critical infrastructure across multiple U.S. states.
Foreign actors gained unauthorized access to the computer systems of two small, private water utilities in Colorado in late August. The attackers altered equipment controls, though operators restored normal operations promptly. The Office of the Governor of Colorado confirmed that water quality and treatment processes remained unaffected, and there was no impact on public safety or water services.
These breaches are part of a wider pattern of cyberattacks targeting U.S. critical infrastructure. In July, water utilities in seven states reported security incidents, including a coordinated attack on more than 30 community water systems in Minnesota. The Michigan Department of Environment, Great Lakes and Energy coordinated responses to these threats, reporting that systems continued to operate safely without public health concerns.
Federal agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the National Security Agency, issued an advisory on August 19 warning that threat actors are using AI-generated scripts to target Siemens S7 Series programmable logic controllers. Officials noted that Iranian-backed groups are specifically targeting outdated or poorly protected internet-connected software within water and wastewater systems.