Hackers Breached Two Colorado Water Utilities in August
The intrusions forced equipment adjustments at small systems, but state officials confirmed water quality remained unaffected.
Updated on Sept. 18, 2026 in Cybersecurity

Live Poll
Do you trust your local utility providers to effectively protect essential infrastructure from cyberattacks?
In late August 2026, two privately owned water utilities in Colorado experienced unauthorized breaches that allowed hackers to alter pumping cycles and disable alarm systems. State health officials confirmed that water treatment and safety were not compromised during the incidents.
Why it matters
The breaches underscore the growing vulnerability of small, internet-connected critical infrastructure to industrial control system attacks. These events mirror a broader national trend, as at least a dozen states have now reported similar cyber incidents targeting water utility technology.
The attackers gained unauthorized access to internet-connected hardware to modify operational equipment settings. While these systems serve fewer than 200 residents each, the breaches represent a significant subset of the 12 states currently confronting cyberattacks on water infrastructure.
The players
Denver Water
A major municipal utility provider serving 1.5 million people that remained unaffected by the August 2026 security events.
The details
The attackers targeted industrial control systems—the hardware that automates physical processes like pumping—to disable remote access and override security alarms. By manipulating these settings, the intruders were able to alter pumping cycles directly. Following the detection, local operators coordinated with state health officials to apply security updates and restore control over the internet-connected equipment.
Timeline
July 2026: The FBI reported attacks on water controllers across seven states.
August 2026: A federal advisory warned of active industrial controller cyber threats.
Late August 2026: Two privately owned Colorado water utilities were breached.
The Tech Race
The Colorado breaches follow a pattern established by the July 2026 FBI report on water controller attacks, which documented similar vulnerabilities in seven other states. This indicates an ongoing shift toward targeting small-scale critical infrastructure where security resources are limited.
Residents served by these specific, undisclosed small utilities experienced no disruption to the safety or treatment of their water supply. The incident highlights the potential for small-scale remote access breaches to occur in rural or private water systems without impacting major providers like Denver Water.
The takeaway
These events demonstrate that even small, privately held utilities are now within the operational focus of international cyber threat actors. Residents should monitor future state health department disclosures for updates regarding standardized security mandates for local utility controllers.
Further reading
For more context on how state infrastructure is being hardened against intrusion, visit Cybersecurity.
Live Poll
Do you trust your local utility providers to effectively protect essential infrastructure from cyberattacks?







