A new security study indicates that over a thousand American water and wastewater utilities are vulnerable to cyberattacks due to infostealer malware capable of harvesting employee passwords and active session tokens.
SpyCloud, a cybersecurity defense firm, released findings that highlight how easily critical infrastructure can be compromised amid a recent surge in attacks on water supplies across dozens of U.S. communities.
The research demonstrates that stolen passwords provide a straightforward entry point for hackers into organizational networks, bypassing the need for advanced artificial intelligence tools.
SpyCloud constructed a database containing more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, representing approximately 10,000 organizations. The analysis identified that 1,787 of these entities—nearly one in five—had credentials stolen by infostealers. Among them, at least 250 organizations had exposed credentials that potentially grant access to operational networks and remote-access systems controlling physical water pumps and flow.
The investigation detailed an incident involving an unnamed metering technology provider whose network was infected with password-stealing malware. The malware exfiltrated credentials for 167 U.S. utility companies that depend on the provider. Jason Lancaster, SpyCloud’s chief investigations officer, stated that this single breach effectively gave criminals access to “a hundred otherwise unrelated organizations.”
Infostealers target stored passwords and session tokens, which allow attackers to log in as legitimate users and frequently circumvent multi-factor authentication. These stolen credentials are routinely traded on underground markets to facilitate targeted intrusions.
The report emerges weeks after a series of attacks on U.S. water providers, which the U.S. government has privately attributed to Iran-backed hackers. However, SpyCloud noted no evidence linking those specific Iran-connected attacks to stolen passwords. Instead, those incidents appeared to exploit security flaws such as manufacturer default passwords on mechanical switches and physical controllers, a conclusion consistent with earlier assessments from the Cybersecurity and Infrastructure Security Agency (CISA).
Lancaster emphasized that stolen passwords represent a major, accessible vector for any attacker willing to purchase or locate them, running parallel to the known hardware vulnerabilities in critical infrastructure. He described the water sector as needing to “hold both stories at once” to address the full scope of its security challenges.
Leave a Reply