According to a report by Security Week, external actors have targeted two small water companies in Colorado, manipulating the equipment used to control drinking water systems. The infiltrating reportedly took place in late August this year.
These two private water companies were affected by the recent incident. During the cyberattack, attackers were able to disable remote access, disable alarms, and alter pumping cycles. However, operators quickly regained control of the facility systems.
According to a report in the Denver Post, Ally Sullivan, a spokesperson for the Governor’s Office stated: “We cannot yet confirm exactly which external actors were responsible for this cyber event, but we are aware of ongoing efforts by an Islamic Republic-backed group across the country to access drinking water and wastewater systems.” Given the recent wave of attacks on U.S. infrastructure throughout July, it is believed that Iran played a role in this infiltration. Minnesota, Michigan, South Dakota, Georgia, and Alabama are among the states affected by these continuous attacks. Interestingly, the two affected water facilities serve fewer than 200 customers, and there was no impact on public safety or water services.
The Governor’s Office has not yet named the culprit officially but stated that measures to counter these types of attacks will continue in the future. Attacks by regime-affiliated groups on critical U.S. infrastructure demonstrate a growing threat to Western countries and add to regional tensions. Furthermore, despite a lack of complexity and sophistication, the recent wave of cyberattacks reveals the vulnerability of critical infrastructure.





