1. Basic Information
- Original Title: Foreign actors breach Colorado water systems
- Published Date: 2026-09-18
- Collected Date: 2026-09-22T08:00:36+09:00
- Original Source: Axios Denver
- Severity: high
- Related Sources: SecurityWeek: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
- CVE: None
- Target Products and Services: OT/ICS environments at two privately owned Colorado water utilities
- Threat Actor: Unidentified foreign actors
2. Executive Summary
Unidentified foreign actors breached two small, privately owned water utilities in Colorado, altered equipment settings, disabled remote access and alarms, and changed pumping cycles. The disruptions were brief, and no known impacts on water treatment, water quality, or public safety were reported.
3. Attack Flow
Compromise of Water OT Control
- Threat actors gained unauthorized access to the utilities’ OT environments. The initial-access vector—including whether internet-exposed controllers, remote-access infrastructure, stolen credentials, or another route were involved—has not been disclosed.
- Confirmed operations across the two utilities included modifying device settings, disabling remote access and alarms, and changing pumping cycles. It has not been publicly disclosed which specific actions occurred at each utility.
- The disruptions were brief, and officials said the issues were resolved with no known impact on water treatment, water quality, or public safety.
4. Attacker Location and Execution Point
- Reports establish unauthorized access to the utilities’ OT systems, but the initial-access path and the affected products, services, and assets have not been disclosed.
- It has not been publicly disclosed whether the targeted assets were controllers, SCADA systems, or remote maintenance platforms.
5. Victim and Administrator Perspective
- Victims: No known impacts on water treatment, water quality, or public safety have been reported. Users should check official notices from utility providers or local governments.
- Administrators: Indicators may include unexpected changes to device settings or pumping cycles, loss of remote access, and disabled alarms. Public information does not specify the exact triggers for detection.
6. Success and Failure Conditions
Success Conditions
- The attacker successfully reaches the OT environment or remote access path from the outside.
- The attacker obtains the privileges required to modify device settings, alarms, and pumping cycles.
Failure Conditions
- OT assets are not exposed directly to the internet, and remote access is restricted using MFA, jump hosts, VPNs, and allowlists.
- Controller settings are compared against an approved baseline, and independent paths are maintained for alarms and manual control.
7. What Happens Upon Success
- Modifications to device settings, remote access, alarms, and pumping cycles were confirmed at two utilities.
- There was no known impact on water treatment, water quality, or public safety in this incident. In general, tampering with control settings or pumping cycles can lead to pressure drops, overflows, or treatment process deviations, though none were confirmed to have occurred here.
8. Observable Logs
Because the affected products and initial-access methods have not been disclosed, the following are general investigation recommendations rather than incident-specific observables.
- Email: No reports indicate that email was used for initial access.
- Proxy / SWG / DNS: Review external connections and DNS resolution involving OT remote-access portals or maintenance endpoints. Authentication activity should be verified separately in VPN, identity, or application logs.
- Endpoint / EDR: Check engineering workstations, HMIs, and jump hosts for remote operations, credential access, and configuration file modifications.
- Identity / IdP: Check for abnormal logins to OT and VPN accounts, MFA modifications, and the use of shared credentials.
- SaaS / Cloud: Review configuration changes and operator actions recorded in remote maintenance SaaS, backups, and ticketing systems.
- Network: Check for controller write operations, disabled alarms, pumping commands, and unusual OT protocol activity.
9. Attack Success Determination
Confirmed in Public Information
- OT Manipulation Confirmed: Officials confirmed changes to equipment settings and pumping cycles, as well as the disabling of remote access and alarms. Public reporting does not map each operation to a specific utility.
Determination Criteria for Your Organization
- Initial Execution Confirmed: Corroborate unauthorized OT configuration changes using records of remote sessions, operator accounts, and controller writes.
- Physical Process Impact Confirmed: Correlate unauthorized controller changes with historian data, process variables, alarm states, and independent physical measurements. No such physical impact was publicly confirmed in these incidents.
10. Investigation Playbook
- Trigger: Start with unexpected pumping cycles, stopped alarms, loss of remote access, and configuration differences.
- Initial Verification: Prioritize process safety by checking manual control and water quality, then identify affected assets and remote sessions.
- Endpoints: Preserve HMI and engineering workstation images, controller settings, historians, and alarm logs.
- Authentication and Cloud: Check usage history for VPNs, maintenance vendors, shared accounts, MFA, and jump hosts.
- Subsequent Operations: Track activity involving neighboring utilities, the same controller models, or identical credentials and source IPs.
- Containment: Coordinate with plant operators and, when operationally safe under established procedures, transition to manual control, restrict affected remote-access paths, rotate credentials, and restore configurations from a trusted baseline.
- Classification: Differentiate between IT access, OT authentication, configuration changes, disabled alarms, and physical process impacts.
11. Defense and Detection Ideas
- Single Events: Detect unauthorized controller writes, disabled alarms, and pumping schedule changes with high priority.
- Timeline Correlation: Correlate remote logins, engineering operations, stopped alarms, and process variable deviations chronologically.
- Hunting: Hunt across all sites for internet-exposed OT assets, default or shared credentials, and recent configuration differences.
- Log Gaps: Without OT protocol visibility and operator logs, it is difficult to distinguish between legitimate maintenance and unauthorized operations.
- Priority Countermeasures: Prioritize eliminating direct exposure, implementing jump hosts with MFA, maintaining asset inventories, backing up configurations, and establishing out-of-band alarms.
12. Facts / Inference / Hypothesis
Facts
- In late August 2026, two privately owned water utilities in Colorado, each serving fewer than 200 people, were compromised.
- Attackers modified device settings, disabled remote access and alarms, and changed pumping cycles. Public information does not map specific operations to either of the two utilities.
- The disruption was resolved quickly, with no known impact on water treatment, water quality, or public safety.
- The attackers have not been identified, the initial-access vector has not been publicly disclosed, and no connection to Iran-linked activity elsewhere has been confirmed.
Inference
- Environments that combine stopped alarms with control setting modifications can interfere with physical processes while reducing operator visibility. However, it remains unclear whether the same attackers performed operations in the same sequence at both utilities.
Hypothesis
No additional hypotheses. Unconfirmed items are listed under "Unknowns and Further Investigation."
13. MITRE ATT&CK Mapping
- T0831 Manipulation of Control (Confidence: High): Attackers actually modified OT device settings and pumping cycles.
- T0878 Alarm Suppression (Confidence: High): Officials confirmed that the attackers disabled alarms, reducing operators’ visibility into process conditions.
14. Unknowns and Further Investigation
- Initial access vectors, vendors and models of affected controllers, credential usage, vulnerabilities, and threat actors.
- The settings and operations altered at each utility, the duration of unauthorized access, and the on-site detection triggers.
- Whether the same activity is expanding to other states or other water utilities.
15. Impact on SOCs and Organizations
Small water and wastewater utilities face similar risks regarding remote maintenance, shared credentials, internet-exposed controllers, and single-system alarms. Even in incidents where no safety impacts are confirmed, configuration changes and disabled alarms represent critical control boundary violations. Recovery should not rely solely on network restoration; organizations must compare approved engineering settings with independent physical measurements to confirm a return to a safe state.
16. Summary by Target Audience
- SOC: Correlate remote access, controller settings, disabled alarms, and pumping schedule changes using operator logs and network telemetry.
- Administrators: Eliminate direct exposure of OT assets, apply MFA, jump hosts, and allowlists to remote access, and verify configuration backups and alarm independence.
- Users: No known impacts on water quality or safety have been reported. Follow official notices from utility providers and local governments.
Top comments (0)