Infostealer malware exposed credentials at nearly 20% of US water and wastewater organizations, SpyCloud finds
A SpyCloud study found that 1,787 of roughly 10,000 U.S. water and wastewater organizations — nearly 20% — have active credential exposure from infostealer malware, including 250 with exposed access to operational networks and remote-access systems, though…
SpyCloud analyzed 66,000 EPA-registered public-facing systems across approximately 10,000 U.S. water and wastewater organizations and found that password-stealing malware had compromised credentials at 1,787 providers — nearly two in ten. At least 250 of those organizations had exposed credentials granting access to operational networks and remote-access systems that control pumps and water flows. The stolen data includes passwords and session cookies/tokens, which could allow attackers to bypass multifactor authentication and reach critical systems. In one case, a single infected device at an unnamed smart meter technology provider exposed saved logins for 167 different U.S. utility metering tenants, illustrating cascading supply chain risk. The research follows reports of cyberattacks on water systems potentially linked to Iran, but SpyCloud found no evidence that those recent hacks relied on stolen passwords; the Iran-linked activity instead exploited default passwords in infrastructure controllers.
- SpyCloud analyzed 66,000 EPA-registered public-facing systems across approximately 10,000 U.S. water and wastewater organizations.
- 1,787 organizations — nearly 20% (nearly two in ten) — had active identity data exposure from infostealer malware.
- At least 250 organizations had exposed credentials granting access to operational networks and remote-access systems controlling pumps and water flows.
- A single infected device at an unnamed smart meter technology provider exposed saved logins for 167 different U.S. utility metering tenants, demonstrating supply chain risk.
- Exposed data includes passwords and session cookies/tokens that can bypass multifactor authentication.
- SpyCloud found no evidence that recent Iran-linked water-sector hacks relied on stolen passwords; those attacks instead exploited default passwords in infrastructure controllers.
- The research follows reports of cyberattacks on water systems potentially linked to Iran.
Coverage timelineoldest first · each row is one article
- · 4d agoAnother worry for water systems: infostealer exposure
CyberScoop· 75
SpyCloud study finds nearly 20% of U.S. water/wastewater organizations have active infostealer credential exposure.
- · 4d agoStolen passwords are exposing America’s water providers to hackers
TechCrunch · Security· 55
SpyCloud research found infostealer malware stole credentials from 1,787 US water providers, including 250 with operational-network and remote-access exposure.