ap

Skip to content

‘Foreign actors’ briefly hacked two small Colorado water utilities last month, state says

Governor’s office says it’s unclear who was involved, but Iran-backed group was linked to similar attacks

Denver Post reporter Seth Klamann in Commerce City, Colorado on Friday, Jan. 26, 2024. (Photo by Andy Cross/The Denver Post)
PUBLISHED: | UPDATED:
Getting your player ready...

Foreign actors gained access to two small water utility systems in Colorado late last month, state officials confirmed, just weeks after hackers with suspected links to Iran had attempted to access similar systems elsewhere in the United States.

It’s unclear who the actors were or if the attempted interference was related to the July hacking attempts that affected . Gov. Jared Polis’ office told The Denver Post that the computer systems for two Colorado utilities — both of which are private and serve fewer than 200 people — were targeted in late August.

But his office said that, to the state’s knowledge, “treatment processes and water quality were not impacted at either provider,” similar to the outcome in of reported hacking efforts in other states.

“These two incidents consisted of individuals changing equipment settings, disabling remote access and alarms, and altering pumping cycles,” Polis spokeswoman Ally Sullivan said in a statement. “These were brief incidents, and the risks were quickly addressed by the providers themselves, who subsequently alerted the state.”

“We cannot confirm what foreign actors may have been involved, but we are aware of ongoing efforts across the nation by an Iranian-backed group to access drinking water and wastewater systems, as per ,” Sullivan wrote in a separate statement.

Polis’ office declined to identify the two utilities affected. The Colorado Rural Water Association did not return messages seeking comment, nor did the federal cybersecurity agency.

Vikki Migoya, a spokeswoman for the FBI in Denver, said the agency “typically does not comment on the existence or status of any investigative work” it may be conducting.

, the FBI and several other federal agencies warned of “Iranian-affiliated” threats that were seeking to “cause disruptive effects within the United States,” and against water and energy systems specifically.

In early August, after several states reported hacking attempts, former intelligence officials and cybersecurity experts that hackers were likely acting opportunistically rather than targeting specific local governments. That potentially put any facility using vulnerable internet-connected operational systems at risk.

The Times reported that federal cybersecurity officials urged water utilities to unplug internet-connected controllers that might make them targets.

Sullivan, Polis’ spokeswoman, said the state was monitoring national trends and state officials “are communicating with Colorado providers, encouraging them to double-check their security measures and make any necessary security updates.”

In comments to state lawmakers last week, Sarah Tuneberg, Colorado’s chief information officer, said the state had, “over the last few months, had an uptick in external international actors attempting to attack our infrastructure.”

That includes concerns — which have not been realized — that North Korean “threat actors” may be “attempting to gain employment (information) and access our systems.”

Polis’ office said it was distributing new guidance to state agencies — including requiring live videos for interviews of job candidates and in-person identity checks — to cut down on the risk of those threats.

More in Politics