OT / ICS Security · Credential Theft
Colorado Water Utilities Saw Quiet OT Tampering Two small private water utilities in Colorado were hit in late August, and officials said the attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles. The incidents affected operational technology, not just IT, and the utilities did not report service outages or public-safety impact.
In plain terms, the intruders got into the control layer and changed how the pumps and monitoring systems behaved. That matters because a site can keep running while alarms go dark and remote access stops working, which makes the compromise harder to spot and slower to sort out.
For water systems and other remote-managed physical processes, the lesson is that continuity does not prove control. If the attacker can change settings without knocking service offline, the longer exposure is the loss of trust in alarms, remote access, and process state even after operations look normal.
3 sources · Sep 22
Timeline Sources Sep 22 TechCrunch Security
Stolen passwords are exposing America's water providers to hackers | TechCrunch
Researchers say another looming threat hangs over some of America's most important critical infrastructure.
original Sep 22 Industrial Cyber
Colorado water utilities face foreign cyberattacks targeting pumps, alarms and remote access - Industrial Cyber
Colorado water utilities face foreign cyberattacks targeting pumps, alarms and remote access amid broader US water sector threats.
original Sep 21 SecurityWeek
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said.
original Part of the PlainSec briefing for 2026-09-22
Every edition of this story: Colorado Water Utilities Saw Quiet OT Tampering
OT / ICS Security · Credential Theft
Colorado Water Utilities Saw Quiet OT Tampering Two small private water utilities in Colorado were hit in late August, and officials said the attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles. The incidents affected operational technology, not just IT, and the utilities did not report service outages or public-safety impact.
In plain terms, the intruders got into the control layer and changed how the pumps and monitoring systems behaved. That matters because a site can keep running while alarms go dark and remote access stops working, which makes the compromise harder to spot and slower to sort out.
For water systems and other remote-managed physical processes, the lesson is that continuity does not prove control. If the attacker can change settings without knocking service offline, the longer exposure is the loss of trust in alarms, remote access, and process state even after operations look normal.
3 sources · Sep 22
Timeline Sources Sep 22 TechCrunch Security
Stolen passwords are exposing America's water providers to hackers | TechCrunch
Researchers say another looming threat hangs over some of America's most important critical infrastructure.
original Sep 22 Industrial Cyber
Colorado water utilities face foreign cyberattacks targeting pumps, alarms and remote access - Industrial Cyber
Colorado water utilities face foreign cyberattacks targeting pumps, alarms and remote access amid broader US water sector threats.
original Sep 21 SecurityWeek
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said.
original Part of the PlainSec briefing for 2026-09-22
Every edition of this story: Colorado Water Utilities Saw Quiet OT Tampering