Cybersecurity firm SpyCloud identified that 1,787 U.S. water and wastewater providers, representing nearly 20% of those checked, have been affected by password-stealing malware. This malware compromises employee passwords and active logged-in sessions, creating an entry point for hackers into critical infrastructure systems.
The research covered over 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, encompassing 10,000 organizations. Among the compromised, at least 250 organizations had credentials exposed that could grant access to their operational networks and remote-access systems, which control physical water pumps and flows.
An analysis highlighted a specific incident involving an unnamed metering technology provider. A device on this provider's network was infected with password-stealing malware, leading to the theft of credentials for 167 U.S. utility companies that rely on its services. SpyCloud's Chief Investigations Officer, Jason Lancaster, stated that this single breach provided criminals with access to numerous unrelated organizations.
Password-stealing malware, also known as infostealers, captures stored passwords and session tokens. Session tokens allow hackers to bypass multi-factor authentication and log in as legitimate users. Stolen credentials are frequently traded among hackers to gain access to specific organizations.
This research follows recent hacks targeting U.S. water providers, which the U.S. government has attributed to Iran-backed actors. However, SpyCloud found no evidence that these specific Iran-linked attacks utilized stolen passwords. Instead, those incidents pointed to security weaknesses such as manufacturer-set default passwords in mechanical switches and physical controllers.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
New research by SpyCloud reveals that 1,787 U.S. water and wastewater providers have had employee passwords and active logged-in sessions compromised by password-stealing malware. This exposure allows hackers to access operational networks and remote-access systems, posing a risk to critical infrastructure.