Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Foreign Hackers Breach Two Colorado Water Utilities, Manipulate Pumps and Alarms

What happened
Foreign hackers broke into the computer systems of two small, privately owned water utilities in Colorado in late August, according to Gov. Jared Polis' office. The intruders changed pumping cycles, disabled alarms, altered equipment settings and cut off remote access before operators regained control, spokeswoman Ally Sullivan told The Denver Post and Axios.
Both utilities serve fewer than 200 people each, for a combined total of roughly 400 residents. Polis' office says treatment processes and drinking water quality were not affected. The state says the providers caught the intrusions themselves and reported them.
Polis' office has not named the two utilities, has not identified who carried out the attacks, and has not said whether the incidents are connected to similar breaches reported elsewhere in the country. The FBI's Denver office, through spokeswoman Vikki Migoya, said it does not comment on the existence or status of investigations. No charges have been filed and no formal attribution has been announced.
Part of a bigger pattern
Colorado joins a growing list of states dealing with attacks on water infrastructure. The Environmental Protection Agency says more than 100 drinking water and wastewater systems across 12 states have been targeted this year. In July, the FBI and EPA warned that hackers were remotely accessing internet-facing programmable logic controllers, or PLCs. These devices physically run pumps and valves at treatment plants, and in some cases have knocked out monitoring and control capability entirely. Reported effects elsewhere included loss of water pressure and flooding.
Minnesota got hit hardest so far, with cyber activity affecting more than 30 community water systems this summer, forcing some utilities onto manual backup procedures, according to Fox News.
The Iran question, unresolved
Sullivan said Colorado "cannot confirm what foreign actors may have been involved" in the August breaches, but added the state is "aware of ongoing efforts across the nation by an Iranian-backed group to access drinking water and wastewater systems," citing guidance from the Cybersecurity and Infrastructure Security Agency.
Federal agencies warned in April that Iranian-affiliated actors were seeking disruptive effects against U.S. water and energy systems specifically. But President Trump has pushed back hard on pinning the earlier Minnesota attacks on Iran. "They blame it on Iran. I don't think so," Trump said during a Cabinet meeting, instead placing blame on Minnesota officials. No federal agency has publicly attributed the Colorado breaches to any specific country or group, so the Iran link remains an open question, not a confirmed fact.
Steve Bucci, a former top Pentagon official and Heritage Foundation visiting fellow, told Fox News's "Fox & Friends First" the pattern reflects a growing cyber threat to U.S. water infrastructure broadly, regardless of which specific actor is behind any single incident.
Why small systems keep getting hit
Colorado's chief information officer, Sarah Tuneberg, told state lawmakers the state has seen "an uptick in external international actors attempting to attack our infrastructure" over recent months, including concerns tied to North Korea that "have not been realized," according to The Denver Post.
Former intelligence officials told The New York Times, as cited by The Denver Post, that hackers appear to be acting opportunistically rather than targeting specific towns. Any utility running internet-connected control systems is a potential target regardless of size. Federal officials have urged utilities to disconnect internet-facing controllers where possible.
Small and rural systems are the most exposed because they run lean, often relying on remote monitoring tools with limited in-house security staff. That's precisely the profile of the two Colorado utilities involved: private operations serving under 200 customers each, without the budget of a major metro system.
By contrast, Denver Water, which serves about 1.5 million people, told Axios it evaluated the threat after the Colorado incidents came to light and determined its own systems weren't affected.
What's next
Colorado health officials say they've offered technical assistance to the affected providers and alerted other water systems statewide to check their security. The EPA says it has identified additional vulnerabilities across the country since fiscal year 2025 as part of its broader hardening push with states and federal partners.
What remains unanswered: whether the Colorado intrusions are linked to the Minnesota attacks or the broader 12-state campaign the EPA has tracked this year, whether the FBI has opened a formal investigation into either Colorado utility, and whether any nation-state will ever be publicly named. Until federal investigators say otherwise, the attackers responsible for turning off alarms and rerouting pumps at two small Colorado water plants remain unidentified.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.