CRBC News
Security

SpyCloud: Malware Harvested Logins From 1,787 U.S. Water Providers — Vendor Device Exposed Credentials Tied To 167 Utilities

SpyCloud: Malware Harvested Logins From 1,787 U.S. Water Providers — Vendor Device Exposed Credentials Tied To 167 Utilities
Photo Credit: iStock

SpyCloud's analysis found credential‑stealing malware had harvested logins from 1,787 U.S. water and wastewater organizations after scanning roughly 10,000 entities and over 66,000 EPA‑registered outward‑facing systems. Credentials from at least 250 organizations appeared capable of reaching operational networks and remote‑access tools used to run pumps and control water flows, and a single infected vendor device exposed passwords tied to 167 utilities. While some recent breaches were privately linked to Iran‑backed actors, SpyCloud found no evidence stolen passwords caused those incidents; nonetheless, stolen credentials and session tokens remain a major, parallel threat to critical infrastructure.

A new analysis by cybersecurity firm SpyCloud found that credential‑stealing malware has captured employee login data from 1,787 U.S. water and wastewater organizations. The company reviewed roughly 10,000 organizations by scanning more than 66,000 outward‑facing systems registered with the U.S. Environmental Protection Agency, according to reporting in TechCrunch.

What SpyCloud Found

SpyCloud determined that credentials harvested from about 20% of the surveyed providers could be in criminal hands. In at least 250 organizations, the stolen logins appeared capable of reaching operational networks and remote‑access tools used to run pumps and control water flows. In a separate case study, an infected device on an unnamed metering‑technology vendor's network contained passwords tied to 167 U.S. utility companies.

“The compromise effectively handed criminals the keys to a hundred otherwise unrelated organizations,” said SpyCloud chief investigations officer Jason Lancaster.

How Infostealers Amplify Risk

Infostealer malware does more than capture saved usernames and passwords. SpyCloud and TechCrunch noted these infections can also exfiltrate session tokens that keep users signed in, enabling attackers to impersonate legitimate users and, in some cases, bypass multi‑factor authentication protections. Because many water systems rely on interconnected vendor services and remote‑access tools, credential exposure can allow attackers to move laterally into operational technology (OT) environments.

Context: Recent Water‑System Breaches

The report follows a spate of breaches at U.S. water providers. U.S. government officials have privately attributed some of those incidents to Iran‑linked threat actors, but SpyCloud found no evidence that stolen passwords directly caused those specific attacks. Instead, those breaches appear to have exploited other weaknesses—such as factory‑default passwords on mechanical switches and controllers—underscoring that attackers use multiple avenues to gain access.

Why This Matters

Water systems are a uniquely sensitive target. Disruptions to networks that manage drinking water distribution and wastewater treatment can affect public health, local economies, and essential daily services. The sector's interconnectedness—infrastructure, vendors, and administrative systems—means a single compromised laptop or vendor account can have far‑reaching consequences.

Recommended Actions

SpyCloud emphasized that protecting both identity and operational‑technology attack surfaces is essential. Key defenses include:

  • Immediate inventory and remediation of exposed credentials and saved session tokens;
  • Vendor‑risk assessments and network segmentation to limit lateral movement from vendor environments to OT systems;
  • Eliminating factory‑default passwords and enforcing strong credential hygiene and multi‑factor authentication across devices and management interfaces;
  • Continuous monitoring for infostealer infections and compromised sessions.

“The identity exposure sitting around this sector — a vendor's infected laptop, a stolen session, a saved remote‑desktop password — is real, current, and largely invisible to the utilities it puts at risk,” the SpyCloud report warned. The firm concluded: “Neither [identity security] one is optional, and neither substitutes for the other.”

Beyond cybersecurity, the water sector also faces other pressures such as invasive species spread through raw‑water transfers and regulatory and contamination challenges related to PFAS, underscoring the broader risks to water systems nationwide.

Help us improve.

Related Articles

Trending