/

September 22, 2026

Fewer Than 200 People: What the Colorado Water Utility Hacks Say About Being Too Small to Target

Two water utilities in Colorado were broken into in late August. The attackers got into the systems that control drinking water equipment, changed equipment settings, altered pumping cycles, disabled remote access, and switched off the alarms. Operators regained control, the disruptions were brief, and state officials say there was no impact on water treatment, water quality, or public safety.

Now here’s the number that makes this story matter to you. Each of those utilities serves fewer than 200 people.

Not two hundred thousand. Two hundred. That’s smaller than a lot of the businesses reading this. It’s a customer base you could fit in a school gym. And it was still worth somebody’s time to break in and start turning dials. If you have ever told yourself that your business is too small to interest an attacker, this is the story that should end that conversation for good.

We’ve been following attacks on physical infrastructure all year — a series that started with more than 30 community water systems in Minnesota, moved through thousands of exposed industrial controllers, a power plant in Poland, and a pair of oil tankers boarded at sea. Colorado is the latest chapter, and it has the clearest lesson yet.

What’s confirmed

Colorado Governor Jared Polis’s office confirmed the incidents to multiple news outlets. Here’s what the state has said:

  • Two privately owned water utilities, each serving fewer than 200 people, were breached in late August. The state has not identified them.
  • The attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, according to a spokesperson for the governor.
  • Operators regained control. The disruptions were brief, and to the state’s knowledge treatment processes and water quality were not affected at either provider.
  • Colorado is not alone. The Environmental Protection Agency has said high-profile cyberattacks have targeted more than 100 drinking water and wastewater systems across 12 states this year.

One honest note on attribution, because it’s worth modeling careful reading. State officials described the attackers as “foreign actors” — and in the same breath said they could not confirm which foreign actors were involved and had not determined who was behind the breaches. The governor’s spokesperson noted that federal officials are tracking an effort by an Iranian-backed group to access water systems nationwide, but the state did not attribute these incidents to it. Several commentators have fairly pointed out the tension there: if you can’t say who did it, the “foreign” label is an assessment rather than a finding. We’ll leave attribution to investigators and take no position on it. The lesson doesn’t depend on it at all.

Nobody picked these utilities. That’s the point.

Why would anyone target a water system serving 200 people? The honest answer is that they very likely didn’t target it — not in the way we usually imagine.

Former intelligence officials and security experts have described this wave of water-sector attacks as opportunistic rather than aimed at particular towns. The pattern that emerged this summer is consistent: attackers scan the internet for industrial control equipment that’s reachable from outside, then break into whatever they find that’s poorly protected. The victim isn’t chosen for its size, importance, or location. It’s chosen because its equipment answered when someone knocked.

This is the single most important idea for a small business to absorb: you are not being evaluated as a target. You are being scanned. Automated tools sweep the entire internet constantly, and they don’t know or care whether the thing that responds belongs to a Fortune 500 company or a utility with 200 customers. They just record what’s exposed and whether it’s weak. “We’re too small to be worth it” assumes somebody is weighing whether you’re worth it. Nobody is. The only question being asked is whether your door is open.

We saw exactly this when a research scan found thousands of industrial controllers sitting openly on the public internet, and again when attackers deliberately went after small, lightly defended facilities instead of hardened ones. Colorado is the same pattern at its most extreme: the smallest target in the whole series, reached for the same reason as all the others.

They turned off the alarms first

Look closely at the list of what the attackers actually did, because one item in it deserves far more attention than it’s getting. They changed settings and altered pumping cycles — the part that sounds dramatic. But they also disabled the alarms and disabled remote access.

Think about what that means. The alarms are how an operator finds out something is wrong. Remote access is how they respond from wherever they are. By switching off both, an attacker isn’t just changing how the equipment behaves — they’re removing the operator’s ability to notice the change and removing their ability to fix it without physically going to the site. That’s a deliberate sequence: blind the defender, then lock them out.

The small-business translation is direct and a little uncomfortable. Your monitoring is itself a target. The camera system that records your back door, the alert that emails you when the walk-in cooler warms up, the notification when someone logs into your accounts, the backup job that tells you it succeeded — an attacker who gets in will often go after those first, because the thing that tells you something’s wrong is the thing standing between them and time. That’s why we keep saying the alarm that nobody checks is not really an alarm, and why it matters whether your alerts go somewhere that can’t be switched off from the same place the attacker is sitting.

Why the utilities were fine

Here’s the encouraging part, and it’s genuinely instructive. Despite all of that, the operators got control back and the water was never affected. How?

The state hasn’t described the response in detail, so we won’t pretend to know exactly what happened in Colorado. But we can point to what worked elsewhere in this same wave. When attackers hit water systems in Minnesota earlier this year, some utilities switched to manual operations and backup procedures and kept the water flowing. The pattern that protects people in these incidents is consistent: somebody noticed, the equipment could be run by hand, and the humans knew how to do it.

That’s a lesson for any business that depends on connected equipment. If your systems went dark tomorrow, could you keep operating by hand for a day? Could you take orders on paper, open the doors with a key, run the equipment on its manual settings, reach your staff without your usual tools? The businesses that ride out incidents aren’t always the ones with the best technology. Often they’re the ones that never let themselves become completely dependent on it.

The federal advice is refreshingly simple

Amid all the complexity of this story, the guidance federal cybersecurity officials gave water utilities this summer was about as plain as security advice gets: unplug internet-connected controllers that don’t need to be online.

That’s it. Not a product. Not a platform. If a piece of equipment doesn’t have a genuine reason to be reachable from the internet, take it off the internet, and it stops being findable by the scanners that found these utilities. A great deal of connected equipment is exposed simply because that was the easiest way to set up remote monitoring years ago, and nobody has looked at it since.

Your business version of that list is probably longer than you’d expect: security camera recorders, thermostats and building controls, irrigation and gate controllers, the equipment a vendor dials into for maintenance, the old network storage box, the printer with a web page. Each one is a door that answers when the scanners knock.

What to actually do

  1. Find out what’s reachable from the internet. List every connected device in your business, then find out which ones can be reached from outside. This is exactly what the scanners do — you should know the answer before they do.
  2. Unplug what doesn’t need to be online. If there’s no real business reason for a device to be reachable from the internet, remove that access. It’s the federal advice, and it’s free.
  3. Protect what does need remote access. Strong unique passwords, never factory defaults, a second verification step, and access limited to the people and vendors who need it.
  4. Protect your alarms. Make sure alerts go somewhere an attacker can’t easily silence — an email or phone that isn’t controlled from the same system. And make sure somebody actually reads them.
  5. Know your manual fallback. For every connected system your operation depends on, know how you’d run without it for a day, and make sure the people who’d need to do it know too.
  6. Separate your equipment from your office network. As we covered with the tankers, equipment that controls physical things shouldn’t share a network with email and guest Wi-Fi.

Worth asking about your own business: Could you list every device in your business that can be reached from the internet right now? * Do any of them still use their factory passwords? * If an attacker turned off your alerts, would you notice — or would the silence look like everything was fine? * And if your connected systems went dark tomorrow, could you keep operating by hand?

The takeaway

Two water systems serving fewer than two hundred people each were broken into by attackers who switched off the alarms before changing the pumps. Nobody chose them for their importance. Their equipment was reachable, and that was enough. Operators got control back and nobody was hurt — because someone noticed, and because the systems could still be run by people.

Every part of that sentence applies to a small business. You’re being scanned, not selected. Your alarms are a target. And the best protection is often the simplest: take off the internet what doesn’t need to be on it, lock down what does, and know how to keep going when the technology doesn’t.

Our environment review starts exactly where the attackers start: by finding what in your business is reachable from the internet and how well it’s protected. We’ll identify the devices that don’t need to be online, lock down the ones that do, check whether your alerts would survive someone trying to silence them, and make sure a problem with your equipment stays a contained one. A utility with 200 customers found out the hard way that nobody was too small to be scanned. Let’s make sure your business finds out on a quiet afternoon instead.

Sources: Statements from the office of Colorado Governor Jared Polis as reported by Axios Denver, The Denver Post, and others (September 18, 2026); SecurityWeek; Security Affairs; Fox News; iHeart; Environmental Protection Agency figures on water-sector attacks, 2026. State officials have not identified the utilities or determined who was responsible; the “foreign actors” characterization is the state’s, and it has not attributed the incidents to any specific group. This article takes no position on attribution.

From the same category