[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fG_scjUZEt5Ug4ADQMQOd5RW9lgHOAGztKqvRXchvoJ0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"c352734a-859c-4430-abbb-8acbd59031d8","foreign-hackers-alter-ot-settings-at-colorado-water-utilities","e5218dd4-702c-4f2b-b334-0c925f8d98af","Foreign Hackers Alter OT Settings at Colorado Water Utilities","Attackers — believed to be Iranian-backed foreign actors — gained access to operational technology (OT) systems at two Colorado water utilities, directly manipulating equipment settings, disabling alarms, and changing pumping cycles. The incident exposes a critical weakness: OT environments in water infrastructure are frequently internet-accessible with insufficient segmentation and access controls separating them from IT networks and the public internet. While no public safety impact occurred this time, the ability to alter pumping cycles and disable safety alarms represents a direct path to physical harm. This attack pattern mirrors a growing global trend of nation-state actors probing critical infrastructure for vulnerabilities that could be exploited during geopolitical conflict. Water utilities, often under-resourced for cybersecurity, must treat OT security with the same urgency as any public safety function.","**Immediate actions:**\n- Audit and remove all unnecessary remote access pathways into OT\u002FICS systems, replacing them with monitored, MFA-enforced VPN or jump-host solutions.\n- Verify that all OT equipment alarms and safety interlocks cannot be disabled remotely without multi-party authorization.\n- Change all default credentials on PLCs, HMIs, and SCADA components and enforce unique strong passwords across all OT devices.\n\n**Long-term improvements:**\n- Implement strict network segmentation using a DMZ architecture to physically and logically isolate OT\u002FICS networks from corporate IT and the public internet.\n- Establish a formal OT asset inventory and conduct quarterly vulnerability assessments specifically targeting industrial control system components.\n- Develop and regularly exercise an OT-specific incident response plan that includes manual override and failsafe procedures for critical pumping and treatment operations.\n\n**Detection measures:**\n- Deploy OT-aware intrusion detection systems (e.g., Claroty, Dragos, or Nozomi) capable of baselining normal equipment behavior and alerting on configuration changes.\n- Implement centralized logging of all remote access sessions and configuration changes to OT devices, with alerts routed to a 24\u002F7 monitored SOC or MSSP.\n- Subscribe to CISA's Water and Wastewater Sector threat intelligence feeds and configure automated alerts for indicators of compromise linked to known threat actors.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 12 – Network Infrastructure Management","CIS Control 6 – Access Control Management","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-82 – Guide to ICS\u002FOT Security","NIST AC-17 – Remote Access","NIST SI-4 – System Monitoring","NIST IR-4 – Incident Handling","ICS-CERT Recommended Practices for Securing ICS","CISA Cross-Sector Cybersecurity Performance Goals (CPGs) – OT\u002FICS","America's Water Infrastructure Act (AWIA) 2018 – Risk and Resilience Assessments","NERC CIP-005 – Electronic Security Perimeters (adapted guidance for water sector)","published","2026-09-21T12:21:33.717263+00:00","2026-09-21T12:21:33.387+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.securityweek.com\u002Fcolorado-water-utilities-hit-by-cyberattacks-targeting-ot-systems\u002F","colorado-water-utilities-hit-by-cyberattacks-targeting-ot-systems-be507c","Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]