print-icon
print-icon
Add ZeroHedge as a preferred source on Google

Foreign Actors Disrupt 2 Colorado Water Systems: Governor's Office

Tyler Durden's Photo
by Tyler Durden
Authored...

Authored by Kimberly Hayek via The Epoch Times,

Foreign actors gained access to computer systems at two small private water utilities in Colorado in late August, changing equipment controls before operators restored normal operations, according to the governor's office.

Ally Sullivan, a spokeswoman for Gov. Jared Polis, said the Colorado Department of Public Health and Environment followed up with the providers to confirm the issues had been resolved. The governor's office said it was unable to confirm which foreign actors and did not identify the utilities.

"The two water utilities impacted are small, private water providers that serve fewer than 200 people," Sullivan said in a statement to media outlets.

"The providers acted promptly and there was no impact to public safety or water services. We cannot confirm what foreign actors may have been involved, but we are aware of ongoing efforts across the nation by an Iranian-backed group to access drinking water and wastewater systems, as per the Cybersecurity and Infrastructure Security Agency."

Sullivan did not immediately return a request for comment from The Epoch Times.

Treatment processes and water quality were not affected at either provider, according to the governor's office.

The Colorado incidents occurred weeks after a series of cyberattacks impacted water and wastewater systems in multiple states. Federal agencies had already flagged the threat.

In an Aug. 19 advisory, the FBI, National Security Agency, Cybersecurity and Infrastructure Security Agency (CISA), and other agencies warned of an active cyber threat to Siemens S7 Series programmable logic controllers (PLC) used in water systems and other critical infrastructure.

The advisory said unnamed threat actors were conducting reconnaissance and capability development against the U.S.-based Siemens PLC installations, using AI-generated exploitation scripts disguised as legitimate monitoring tools. It noted that the hackers sought internet-connected PLCs running outdated software or that were otherwise poorly protected.

"The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities," the advisory stated.

"This is not a theoretical risk - it is an active threat."

The advisory came amid reports of incidents targeting local water systems in several states in the preceding weeks. The FBI said that from July 27 to July 30, water and wastewater utility companies in seven states reported security-related incidents.

Michigan was among those states. Dale George, director of communications for the Michigan Department of Environment, Great Lakes and Energy, said that the state received the FBI's notice warning of attempts to tamper with operational technology at water systems.

"All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern," George said.

Earlier in July, more than 30 community water systems in Minnesota reported a coordinated cyberattack. CISA urged water entities of all sizes to protect operational technology against activity targeting PLCs.

Attackers had targeted internet-facing Rockwell Automation and Allen-Bradley MicroLogix controllers, changing passwords and IP addresses. Some effects included loss of pressure. Federal officials warned that a significant pressure drop can allow untreated groundwater to enter drinking water pipes.

Reuters contributed to this report.

0