```html ```
top of page

Two Colorado Water Systems Had Their Pumping Cycles Altered. The Reporting Names Zero Indicators. Our 21 From July Are Confidence 90 and Not in the File We Serve.

Writer: Patrick Duggan
Patrick Duggan
1 hour ago
6 min read

Colorado's governor's office disclosed on September 18 that foreign actors reached the control systems of two privately owned water utilities in late August. Each serves fewer than 200 people. The attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles. Treatment processes and water quality were never affected, and the state says there was no impact to public safety or service.


The state also said, carefully, that it cannot confirm who did it. Its spokesperson noted awareness of ongoing efforts by an Iranian-backed group against drinking water and wastewater systems nationally, citing CISA, but drew no line from that campaign to these two utilities. We are going to hold that line exactly where the state drew it, because the useful part of this story does not depend on the flag.



There is nothing to block


We went looking for indicators the way we always do, and there are none. Not a partial set, not a set held back for victims. The public reporting on Colorado names zero IP addresses, zero domains, zero file hashes, and zero CVE identifiers. The device models were not disclosed. The broader campaign record is the same: the July wave that hit Minnesota, Wisconsin, Michigan and South Dakota does not name a software vulnerability or a CVE either.


So we ingested nothing. There was nothing to ingest, and saying so is more useful than manufacturing a list.


This is not a reporting failure. It is what this class of intrusion looks like. There was no malware to hash, no command-and-control to resolve, no exploit to catalog. The publicly documented method for the July wave was remote access to internet-facing devices followed by changing IP addresses and passwords, producing loss of view and in some cases loss of function. The equipment named in that record is Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 series programmable logic controllers, reachable over unauthenticated industrial protocols, alongside human-machine interfaces and cellular modems that operators and vendors installed without always documenting them.


An indicator feed cannot stop that. Ours cannot stop that. The attacker did not bring anything with them; they used the device the way it was configured to be used, from an address nobody had decided was forbidden.





Which half of the control was never assigned


Every failure we find sits at a boundary where two parties each assumed the other had it. This one is textbook.


The integrator or the vendor installs a cellular modem or a remote-access path so the system can be serviced without a two-hour drive, and that is a reasonable thing to do for a utility with no full-time staff. The utility owns its network boundary, and for a system serving 190 people that boundary is frequently one router that came with the service. The equipment manufacturer ships a protocol that was specified in an era when the wire was the perimeter, and that is not a defect in 1998 terms.


Nobody owns the question. Is this device reachable from the public internet today, and does anyone here know it is. That question has no assigned owner at a two-person utility, and the campaign is an efficient harvest of the places where it went unasked.


The second unassigned half is the fallback. The FBI's own read of the July incidents identified whether the utility could still run its process manually as a determining factor in how bad each one got. The utilities that moved to manual operation kept serving water. That is an engineering property, and it belongs to whoever writes the operations procedure, which is usually nobody in particular.



What we actually hold, including the zeros


We have been on this beat since spring and the file is real. Fifteen published posts naming CyberAv3ngers, twenty covering CISA advisory AA26-097A, nine on the Unitronics pattern, seven on water utilities specifically, thirty touching PLCs and twenty-three touching Rockwell. In the indicator index, twenty-two records attributed to CyberAv3ngers, twenty-one of them imported from AA26-097A on July 25 at confidence 90.


The honest zero: we have never published a word about the MicroLogix 1100 or 1400 specifically, which is the equipment family at the center of this campaign. Zero posts. That is a gap in our own coverage of our own standing beat, and we found it by checking rather than by assuming.


On July 30 we published a post whose title was, word for word, "We Said Five Minnesota Water Systems. It Was More Than Thirty. The 21 Indicators Are Still Free." That post is still up, and the background is in "Iran's Water-Plant Crew Just Got a Permanent File in Our Index" from June 30 and "Four Agencies Just Told You to Pre-Build Your Isolation Plan" from July 31.



The correction, which is about us


Those twenty-one indicators are free. They are also not in the file.


We pulled our own served IP blocklist this morning with a registered key and searched it for all twenty-one. Zero of twenty-one are present. Same result in the OPNsense IP blocklist a firewall would consume. They are confidence 90, type ip, well above the confidence 80 floor the feed applies, and they are sitting in the index where a defender cannot reach them by downloading anything.


What is in the file instead: 3,095 rows, of which 1,729 are Spamhaus DROP and 500 are Tor exit nodes. Two redistributed public lists that anybody can get for free from their original publishers, consuming the fetch budget, while our own actor-attributed water-sector research does not make the cut. The cause is a newest-first fetch ceiling on that route — our July import has a static July timestamp and loses the race to lists that rewrite their timestamps on every refresh.


We said the indicators were free. They were published, they were dated, and they were not delivered. That is the distinction this shop keeps relearning: a record in an index is not a record in a feed until the file a defender downloads contains it. We found the same defect in our hash feed earlier today, where 62,500 rows had quietly become 23,110 while the endpoint reported itself complete. The fix for the IP route is understood and is not shipped as of this writing, and we will publish the row count when it is.



What a small utility can do this week, for free


Take our feed first, because it is free and it is ours to offer. The IP blocklist is at /api/v1/opnsense/ip-blocklist, the DNS blocklist at /api/v1/opnsense/dns-blocklist, and the Suricata rules at /api/v1/opnsense/suricata-rules, with setup notes at /api/v1/opnsense/help. All four answered this morning with a registered key, which is free at analytics.dugganusa.com/stix/register. The DNS blocklist is the largest of them and the most useful to a small operator, because it is the one that catches outbound.


Now the honest part. None of those files would have stopped what happened in Colorado. Feeds are for traffic that arrives carrying something you have seen before. This arrived carrying nothing.


The three things that would have stopped it cost no money at all. Find out whether any controller, HMI or cellular modem on your system answers from a public address, including the ones a contractor installed and never wrote down. Change every default and shared credential on the devices that answer. Then run your plant manually for an hour, on purpose, on a Tuesday, and write down what broke, because the utilities in July that could fall back to manual operation kept serving water and the ones that could not lost view of their own process.


That is the whole prescription, and none of it is a product. Our feed is worth running and we will keep making it better in public, including today's admission that a piece of it has not been delivering. But a blocklist is not an inventory, and the device that should never have had a public address is not a detection problem.


Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.




How do AI models see YOUR brand?

AIPM has audited 250+ domains. 15 seconds. Free while still in beta.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=two-colorado-water-systems-had-their-pumping-cycles-altered-the-reporting-names-zero-indicators-ou



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page