Colorado Gov. Jared Polis says foreign actors were involved in a cybersecurity breach that affected two small, private water providers serving fewer than 200 people. The governor’s office said it cannot confirm which actors may have been involved, but cited information from the Cybersecurity and Infrastructure Security Agency about efforts by an Iranian-backed group to access drinking water and wastewater systems.
Details of the cybersecurity breach
The governor’s office said the two utilities were notified in late August and moved quickly to address the incidents. “As required by state regulations, the water service providers notified the State of outside attempts to cause interference in late August, and the providers took quick action to address the incidents and prevent any further interference,” the office said. After notification, the Colorado Department of Public Health and Environment followed up with each provider to confirm the issues had been resolved, offered technical assistance as needed, and shared information with other water providers through the Colorado Water/Wastewater Agency Response Network.
Officials described the incidents as involving changes to equipment settings, disabled remote access and alarms, and modified pumping cycles. “These two incidents consisted of individuals changing equipment settings, disabling remote access and alarms, and altering pumping cycles,” the governor’s office said. The statement added that “to our knowledge, treatment processes and water quality were not impacted at either provider,” and that “the providers acted promptly and there was no impact to public safety or water services.”
The governor’s office did not name the affected providers. State officials said they are monitoring broader national threats to drinking water and wastewater systems and are encouraging providers to review and strengthen security measures.

