Nearly 1 in 5 US Water Utilities Have Exposed Logins from Infostealer Malware
A new study by identity risk firm SpyCloud has found that nearly two in every ten US water and wastewater organisations have identity data actively exposed through infostealer malware. Infostealers are a type of malware that harvest saved passwords, session cookies and autofill information from infected devices, giving attackers ready made access to systems without needing to guess passwords or break through multi-factor authentication.
SpyCloud examined 10,000 organisations linked to Environmental Protection Agency registered water systems and found 1,787 with active infostealer exposure. In one striking case, a single infected device at an unnamed smart meter technology provider contained saved logins connected to around 167 different US utility customers, showing how one small breach can cascade through an entire supply chain.
According to SpyCloud's chief investigations officer Jason Lancaster, stolen session data lets attackers bypass multi-factor authentication entirely by hijacking already logged in sessions, allowing them to quietly access email, VPNs and networks for weeks without detection. The research follows a string of cyberattacks on water utilities this year, some suspected to be linked to Iran, though this particular study does not address the exposed industrial control systems believed to be behind those earlier incidents.