Cyber Incident Victim: Colorado Springs Utilities
Date:
Jun 2022
Location:
United States of America
Summary
Colorado Springs Utilities experienced unauthorized access to a subcontractor's system, compromising data for approximately 200,000 customers. The incident exposed customer names, addresses, account numbers, and—in most cases—phone numbers and email addresses. While the utility asserted the accessed information did not meet statutory thresholds for a "data breach" due to its non-sensitive nature, notifications were issued proactively. The unnamed subcontractor addressed the vulnerability by implementing system enhancements and reinforcing data security policies as agreed with the utility.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On June 15, 2022, an unauthorized party accessed a system belonging to an unnamed subcontractor used by Colorado Springs Utilities, compromising customer data. The utility discovered this incident on July 6, 2022, and began notifying approximately 200,000 affected customers via email on July 13. Exposed information included customer names, physical addresses, Colorado Springs Utilities account numbers, and—for the majority of impacted individuals—phone numbers and email addresses. The utility emphasized that the accessed data did not include sensitive elements such as Social Security numbers, financial account details, or payment card information. Due to the absence of these legally protected data categories, Colorado Springs Utilities stated the event did not meet the statutory definition of a "data breach" under applicable regulations. Nevertheless, the organization proceeded with proactive notifications to inform customers about the exposure of their non-sensitive information.

Colorado Springs Utilities declined to publicly identify the subcontractor involved, citing security concerns as justification for withholding this detail. The utility confirmed the subcontractor had implemented unspecified system enhancements following the incident to strengthen protections for entrusted data. Additionally, the subcontractor revised its policies to ensure compliance with previously agreed-upon security standards for managing Colorado Springs Utilities’ information. No ransomware, data extortion attempts, or further malicious activity stemming from the incident were reported in the disclosure. The utility’s communications focused on transparency regarding the scope of data exposure while reiterating that no critical personally identifiable information or financial data required protective measures like credit monitoring under the circumstances.
