OT / ICS Security · Credential Theft

Colorado Water Utilities Saw Quiet OT Tampering

Two small private water utilities in Colorado were hit in late August, and officials said the attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles. The incidents affected operational technology, not just IT, and the utilities did not report service outages or public-safety impact.

In plain terms, the intruders got into the control layer and changed how the pumps and monitoring systems behaved. That matters because a site can keep running while alarms go dark and remote access stops working, which makes the compromise harder to spot and slower to sort out.

For water systems and other remote-managed physical processes, the lesson is that continuity does not prove control. If the attacker can change settings without knocking service offline, the longer exposure is the loss of trust in alarms, remote access, and process state even after operations look normal.

3 sources · 1 day ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-23

Every edition of this story: Colorado Water Utilities Saw Quiet OT Tampering