Hackers Breached Two Colorado Water Utilities
The cyberattacks affected internet-connected equipment but caused no disruptions to water quality or safety.
Updated on Sept. 18, 2026 in Cybersecurity

Live Poll
Do you trust your local utility providers to effectively protect essential infrastructure from cyberattacks?
In late August 2026, hackers breached two privately owned water utilities in Colorado, altering pumping cycles and disabling alarm settings. State health officials confirmed that water treatment and safety were not impacted by the incidents.
Why it matters
These breaches highlight growing vulnerabilities in small-scale critical infrastructure as federal authorities track active industrial controller threats nationwide. The attacks demonstrate the risks posed to rural systems by adversaries targeting internet-connected operational technology.
The breaches involved unauthorized access to internet-connected equipment settings and alarm systems. While each affected utility serves fewer than 200 people, the attacks were distinct from operations at larger entities like Denver Water, which serves 1.5 million.
The players
Denver Water
This is a large utility provider serving 1.5 million people that was confirmed to be unaffected by the breaches.
Federal Bureau of Investigation
This federal agency monitors cyber threats to national critical infrastructure and reported attacks on water controllers across seven states.
The details
Hackers gained unauthorized entry to the water systems, allowing them to adjust equipment configurations and interrupt remote access protocols. Utilities coordinated with state health officials to apply security updates and technical assistance to restore normal operations.
Timeline
July 2026: The FBI reported cyberattacks on water controllers in seven states.
August 2026: Federal officials issued an advisory regarding active industrial controller cyber threats.
Late August 2026: Two privately owned water utilities in Colorado were breached.
The Tech Race
The incidents underscore a shift where critical infrastructure security is no longer solely a concern for major urban grids. This transition highlights a technological arms race between small, internet-connected utilities and state-sponsored actors targeting legacy operational systems.
While these specific incidents did not impact water safety or treatment, they serve as a reminder of the need for robust security in small-scale utility networks. Customers served by private, rural water providers may see increased implementation of remote access restrictions and security updates.
The takeaway
Small utility systems remain a primary target for global hackers looking to disrupt industrial equipment. Residents should contact their local water provider to ensure the facility follows current federal guidelines for internet-connected system security.
Further reading
Learn more about evolving digital threats in Cybersecurity.
Live Poll
Do you trust your local utility providers to effectively protect essential infrastructure from cyberattacks?










