Hackers Changed Water-Pump Settings at Two Small Utilities

Matthew Mbaka · September 19, 2026 · News

A water utility operator checks a pressure gauge and valve inside a small pump room.

Foreign actors accessed two small drinking-water systems in Colorado in late August and changed how physical equipment operated.

The attackers altered pumping cycles, changed equipment settings and disabled remote access and alarms, according to the Colorado governor’s office. The two privately owned utilities each serve fewer than 200 people.

Officials say the disruptions were brief. There was no known effect on water treatment, water quality or public safety.

That is good news, but it should not soften the central fact: outsiders reached the controls used to move drinking water.

This was more than a stolen password

Many cyber incidents end with exposed records or a locked computer. Operational technology creates a different kind of risk because software is connected to pumps, valves, motors and alarms.

In these Colorado incidents, the attackers did not merely view a dashboard. They changed operating settings.

The state has not named the utilities or identified the attacker. Officials have called the intruders foreign actors, but they have not publicly tied the incidents to a country or group. Reporting from Axios Denver and Reuters agrees on those limits.

Attribution may take time, and it may never become public. Utilities still need to act on what is known.

Small systems carry a large burden

A utility serving fewer than 200 people cannot staff a security operations centre like a major city. It may depend on a local contractor, remote vendor access and control equipment installed long before internet exposure became a routine threat.

Those conveniences are understandable. A technician should not have to drive hours for every adjustment. The trouble begins when a controller, remote desktop tool or maintenance account becomes reachable with weak credentials and little monitoring.

Alarms also deserve special attention. If an intruder can change a pump and silence the warning that would reveal it, a routine response can become a physical safety problem.

The Canadian question

There is no evidence that these Colorado attackers also reached Canadian systems. The lesson still travels.

Canada has thousands of small municipal, private and First Nations water systems. Many operate with tight budgets, older equipment and limited access to specialized cybersecurity staff. A security standard that assumes a large technical team will not fit them.

Useful support has to be practical. Grants should cover replacement of unsupported controllers, secure remote-access equipment and monitoring, not just assessments that leave a small operator with a long report and no money to fix anything.

Every small utility should be able to answer a short list of questions:

Segmentation matters too. Billing, email and office computers should not provide a simple path into the control network. Vendor connections should be opened only when needed and reviewed afterward.

The Colorado systems avoided harm. That makes the incidents useful as a warning rather than a disaster story. Attackers reached the machinery, and small operators elsewhere should not wait for contaminated water or a failed pump before treating that access as urgent.

Tags: cybersecurity, water utilities, critical infrastructure, operational technology, Canada

Read on Mapletechie