
In the US state of Colorado, hackers gained access to the systems of two small water providers and changed equipment settings. Governor Jared Polis said that water quality was not affected. We look at why breaching software is so dangerous and how the cybersecurity of such facilities is maintained.
How they did it
In late August 2026, hackers gained access to the computer systems of two small private water providers in Colorado. Both companies serve fewer than 200 people. The incidents were disclosed by Ellie Sullivan, press secretary for the Colorado governor.
The attackers changed equipment settings, disabled remote access and alarms, and adjusted pump operation cycles. According to state authorities, however, treatment processes and water quality were not affected. The incidents were detected quickly, and the providers blocked further access attempts and notified the authorities.
The Colorado Department of Public Health and Environment then verified that the problems had been resolved, offered the organizations technical assistance, and warned other water system operators. The authorities also urged them to double-check their cybersecurity measures and install the necessary updates.
It is unknown who was behind the attack. Sullivan stressed that authorities can't confirm that the attackers belong to a specific country or group.
Which vulnerabilities help hackers breach utility systems
Even a small utility can become a target for attackers. A small water provider uses the same types of industrial controllers, remote access tools, and automated systems as a large organization.
At the same time, small utilities often lack the money and specialists to build a full cybersecurity program. A small organization may not have a dedicated employee who continuously monitors the security of IT and industrial systems.
Another problem is remote equipment control. Pumps, sensors, and other devices can be managed through programmable logic controllers, or PLCs. Connecting such devices to the internet lets staff manage them remotely, but it also creates another threat. If a controller is reachable from the outside and isn't sufficiently protected, an attacker can hijack access and connect to it remotely.
A stepping stone for hackers: why small organizations are vulnerable
Small utilities can be of interest to attackers not only as targets in their own right. Steve Beatty, a professor at Metropolitan State University of Denver and a cybersecurity expert, suggests that attacks on small organizations are sometimes preparation for larger operations. On a less protected target, attackers can study the infrastructure and test how effective their chosen techniques are.
However, there is no evidence that the two small Colorado water providers were attacked specifically to prepare a larger-scale intrusion. State authorities have not named a specific group behind the incidents or said anything about its future plans.
Even before the Colorado incidents, similar attacks had hit other US water utilities. In July 2026, the US Federal Bureau of Investigation (FBI) and the US Environmental Protection Agency (EPA) reported incidents in at least seven states. The attackers gained access to internet-connected industrial controllers and then changed their IP addresses and passwords. In some cases, this led to a loss of water pressure and flooding.
The agencies also noted that several affected organizations used similar network configurations set up by third-party contractors. This created an additional risk, since an attack method that worked once could be repeated at other facilities.
Large-scale cyberthreats to nations
Water supply is only one sector of critical infrastructure. It also includes communications, energy, transportation, healthcare, and financial and government services. These systems are interconnected. For example, continuous, stable power is needed by water utilities and hospitals alike.
In 2026, cyberattacks in the US affected more than water providers. In March, an attack on the medical device manufacturer Stryker disrupted order processing, production, and product shipments. The same month, a hack of the Los Angeles transit system forced the operator to shut down part of its network, and restoring it took several weeks.
Russian infrastructure faces similar threats. For example, on the evening of April 6, 2026, Rostelecom detected a powerful DDoS attack on its network. To repel it, the operator turned on filtering of incoming traffic, which temporarily restricted access to some internet resources. The outage affected users in at least 30 Russian cities: in just one hour, the monitoring service Detector404 received more than 5,200 complaints about Rostelecom's service.
Overall, from January to May, the number of DDoS attacks in Russia and the CIS grew by 27% year over year. Telecommunications, the financial sector, and government organizations were among the most attacked industries.
The consequences of attacks on such facilities can spread far beyond a single organization. That's why protection against cyberthreats to national security systems covers both IT infrastructure and the operational technology that physical facilities and essential services depend on.
Full risk control and maximum protection of critical infrastructure from cyberthreats
Kaspersky Industrial CyberSecurity helps you monitor OT infrastructure and detect suspicious activity, vulnerabilities, and changes to system settings. The platform is designed to protect critical infrastructure and industrial systems.
Learn more about Kaspersky Industrial CyberSecurityProtecting operational technology: lessons from major players
Operational technology (OT) is the equipment and software that control physical processes at an enterprise, such as the operation of pumps and valves or production lines. OT cybersecurity is especially important because a successful attack can affect the operation of an entire facility.
To build comprehensive OT protection, you need to:
- inventory your equipment and assess risks;
- separate and segment IT and OT networks;
- reduce your organization's attack surface by restricting remote connections and regularly checking which infrastructure components are visible to a potential attacker;
- conduct regular audits and train employees to respond to incidents;
- use specialized solutions to monitor industrial systems and detect threats and anomalies.
Such solutions are already used at large critical infrastructure facilities. For example, at the Leningrad Nuclear Power Plant, Kaspersky Industrial CyberSecurity protects the automated monitoring and control systems of nuclear reactors. The platform covers the infrastructure from SCADA servers and operator workstations to programmable controllers and network equipment.
Related articles and links:
- Understanding cyberthreats to national security systems
- Attack surface management: how to find, prioritize, and reduce exposure
- What is threat intelligence and why does it matter?
Recommended products:
