Foreign actors breached the computer systems of two Colorado water utilities last month, altering equipment settings, disabling alarms, and changing pumping cycles before operators regained control, according to state officials. The incidents, confirmed by the office of Colorado Gov. Jared Polis on Thursday, did not affect drinking water quality or treatment processes. These breaches add Colorado to a growing list of U.S. states experiencing cyberattacks on water and wastewater infrastructure, with the Environmental Protection Agency reporting more than 100 affected systems across 12 states this year.
The two impacted systems provide drinking water to approximately 400 people. While Colorado officials have not yet identified the specific actors behind these intrusions or confirmed if they are connected to broader national activity, the events highlight the vulnerability of operational technology used to control physical equipment such as pumps and valves. Federal authorities warned in July that malicious actors were targeting internet-connected systems at utilities, with the FBI and EPA noting that operators in at least seven states had reported incidents degrading water operations.
What the Left Is Saying
Progressive analysts and infrastructure advocates point to these incidents as evidence of chronic underfunding and neglect in American public utilities. They argue that small and rural utilities, which often lack dedicated cybersecurity staff, have been left exposed due to decades of deferred maintenance and insufficient federal investment in digital resilience. Critics within the Democratic policy sphere contend that the administration's regulatory approach has failed to mandate robust security standards for critical infrastructure, leaving local governments to manage sophisticated cyber threats with limited resources.
What the Right Is Saying
Conservative commentators and officials emphasize the external threat posed by foreign adversaries, particularly state-sponsored actors linked to nations like Iran. President Donald Trump previously disputed suggestions that Iran was behind similar attacks in Minnesota, stating during a Cabinet meeting, "They blame it on Iran. I don't think so," and directing scrutiny toward local state officials. The right argues that the primary focus should be on attribution and retaliatory measures against foreign hackers, as well as reducing reliance on vulnerable internet-facing systems that expose critical infrastructure to global networks.
What the Numbers Show
According to the EPA, more than 100 drinking water and wastewater systems across 12 states have been targeted by cyberattacks this year. Since fiscal year 2025, the EPA has identified over 900 vulnerabilities in more than 650 water systems and helped eliminate approximately 700 of them at over 500 utilities. The agency has also conducted more than 710 cybersecurity risk assessments and provided direct technical assistance to about 15,900 utilities. The specific Colorado incidents affected systems serving 400 residents, with hackers altering programmable logic controllers (PLCs) and disabling remote access and alarms.
The Bottom Line
The Colorado breaches illustrate the expanding surface area of cyber threats to critical infrastructure, moving beyond data theft to operational disruption. While no health impacts were reported in these specific instances, the ability of hackers to alter physical processes like pumping cycles raises safety concerns for water systems nationwide. Federal agencies continue to urge utilities to remove internet-facing programmable logic controllers and strengthen authentication controls. The lack of attribution in the Colorado cases leaves open questions about whether these are isolated incidents or part of a coordinated campaign by foreign actors targeting U.S. infrastructure.