Foreign hackers breached two Colorado water utilities last month, Gov. Polis’ office says
Officials said the brief intrusions changed equipment settings and disabled alarms, but treatment processes and water quality were not affected.
- Research published Tuesday shows nearly two in ten United States water and wastewater organizations have identity data actively exposed to password-stealing malware, according to cybersecurity firm SpyCloud.
- Infostealer malware harvests credentials and session tokens, allowing attackers to bypass multifactor authentication and access corporate email or VPNs without triggering alerts, explained SpyCloud chief investigations officer Jason Lancaster.
- Analyzing 10,000 organizations, the firm found 1,787 with active exposure, including at least 250 with credentials for operational networks and one metering provider breach exposing logins for 167 separate utility tenants.
- Officials revealed Tuesday that foreign hackers breached two small water providers in Colorado last month, altering pumping cycles and disabling alarms, though treatment processes and water quality remained unaffected.
- According to officials, the findings emerge amid broader risks to critical infrastructure, including recent incidents linked to Iranian-backed actors, though SpyCloud noted its research did not focus on operational technology devices.
10 Articles
10 Articles
Another worry for water systems: infostealer exposure
An exclusive SpyCloud report reveals nearly 1,800 EPA-registered water systems and utilities face active infostealer malware exposure, highlighting widespread supply chain risks.
Foreign hackers breached two Colorado water utilities
Two small, privately owned Colorado water utilities were breached by foreign hackers in August, according to the governor’s office. The office says it remains unclear what foreign actors may have been involved in the breach.
Stolen passwords are exposing America's water providers to hackers | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker - National Cyber Security Consulting
New security research has found that well over a thousand U.S. water and wastewater providers are exposed to hacks due to malware that’s capable of stealing their employees’ passwords and active logged-in sessions. The findings by cybersecurity defense firm SpyCloud underscore how water providers and other critical infrastructure can be compromised with relative ease amidst […] Thank you for subscribing to our RSS feed!
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
Hackers targeted operational technology (OT) systems at two private water utilities in Colorado in late August, apparently attempting to cause disruptions. Few technical details are available, but it seems the attackers targeted industrial control systems (ICS) at the water utilities, which serve fewer than 200 people. A spokesperson for Colorado Governor Jared Polis told The […]
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











