Hackers Reached Colorado Water Controls Without Stopping the Pumps
Attackers reached the operational technology at two small Colorado water providers and changed equipment settings. Officials say alarms were affected and pumping cycles alternated, but the pumps continued to run and no interruption to water service or public-safety impact was reported.
Axios reported the governor’s office statement on 18 September. KRDO’s local report says the incidents affected two private providers serving fewer than 200 customers and describes changed settings, disabled remote access and alarms, and alternating pumping cycles.
Changed settings are serious, but they are not contamination
The public account supports unauthorised access to control settings. It does not establish that attackers contaminated water, damaged equipment, stopped service or gained control of utilities across the state. The providers disabled remote access while responding, and officials said operations continued safely.
That distinction should not minimise the event. Manipulating alarms and pumping schedules can reduce an operator’s confidence in what the control system is reporting. Even when the physical process remains within safe limits, the organisation must decide which settings, histories and remote-access paths can still be trusted.
Small utilities carry the same physical consequences
A provider with fewer than 200 customers may have limited security staff, older equipment and a strong operational reason to retain remote access. Its size reduces neither the importance of safe water nor the need for evidence when settings change unexpectedly.
The reviewed reporting describes the attackers as foreign but does not publicly name a country or group. BlackTree found no direct technical incident bulletin with indicators, affected products or a root cause. Attribution and initial access should therefore remain open questions.
Operational response priorities
- Inventory every remote route. Include vendor access, cellular gateways, VPNs, remote desktops and shared support accounts.
- Preserve the control history. Export alarm, configuration, authentication and engineering records before resetting or rebuilding equipment.
- Compare with known-good settings. Validate pumping schedules, thresholds and alarm behaviour with operations staff.
- Segment without blinding operators. Remote access can be disabled during containment, but safe local operation and monitoring must remain available.
- Reset trusted access. Rotate credentials and certificates only after scoping what was reachable and retaining evidence.
- Exercise manual operation. Small providers need a tested way to run safely while remote management is unavailable.
The useful lesson is not that catastrophe was narrowly avoided. It is that attackers crossed from business technology into operational settings, and the operators still contained the event without a service or safety failure. That boundary crossing deserves attention even when the water kept flowing.
Sources
- Axios Denver, governor-office account, published 18 September 2026 at 17:58 UTC.
- KRDO, local report on the two providers, published 18 September 2026 at 17:23 as displayed.


