
Colorado Gov. Jared Polis speaks at CS Wind in Pueblo, Colo., on Nov. 29, 2023. Michael Ciaglo/Getty Images
Foreign actors gained access to computer systems at two small private water utilities in Colorado in late August, changing equipment controls before operators restored normal operations, according to the governor’s office.
Ally Sullivan, a spokeswoman for Gov. Jared Polis, said the Colorado Department of Public Health and Environment followed up with the providers to confirm the issues had been resolved. The governor’s office said it was unable to confirm which foreign actors and did not identify the utilities.
“The two water utilities impacted are small, private water providers that serve fewer than 200 people,” Sullivan said in a statement to media outlets. “The providers acted promptly and there was no impact to public safety or water services. We cannot confirm what foreign actors may have been involved, but we are aware of ongoing efforts across the nation by an Iranian-backed group to access drinking water and wastewater systems, as per the Cybersecurity and Infrastructure Security Agency.”
Sullivan did not immediately return a request for comment from The Epoch Times.
Treatment processes and water quality were not affected at either provider, according to the governor’s office.
The Colorado incidents occurred weeks after a series of cyberattacks impacted water and wastewater systems in multiple states. Federal agencies had already flagged the threat.
The advisory said unnamed threat actors were conducting reconnaissance and capability development against the U.S.-based Siemens PLC installations, using AI-generated exploitation scripts disguised as legitimate monitoring tools. It noted that the hackers sought internet-connected PLCs running outdated software or that were otherwise poorly protected.
“The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities,” the advisory stated. “This is not a theoretical risk—it is an active threat.”
The advisory came amid reports of incidents targeting local water systems in several states in the preceding weeks. The FBI said that from July 27 to July 30, water and wastewater utility companies in seven states reported security-related incidents.
“All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern,” George said.
Attackers had targeted internet-facing Rockwell Automation and Allen-Bradley MicroLogix controllers, changing passwords and IP addresses. Some effects included loss of pressure. Federal officials warned that a significant pressure drop can allow untreated groundwater to enter drinking water pipes.
Reuters contributed to this report.

