New security research has revealed that more than a thousand US water and wastewater providers are exposed to hacks. This vulnerability stems from malware capable of stealing employees' passwords and active logged-in sessions.
The findings by cybersecurity defence firm SpyCloud highlight how critical infrastructure, including water providers, can be compromised. The firm analysed over 66,000 public-facing systems registered with the US Environmental Protection Agency, representing 10,000 organisations.
SpyCloud discovered that password-stealing malware had swiped credentials from 1,787 organisations, nearly two in ten of those checked. At least 250 of these organisations had exposed credentials that appeared to allow access to their operational networks and remote-access systems, which control physical pumps and water flows.
One incident involved an unnamed metering tech provider whose network device was infected with password-stealing malware. This breach stole credentials, including passwords for 167 US utility companies reliant on that provider. Jason Lancaster, SpyCloud's chief investigations officer, stated this single breach provided criminals with access to "a hundred otherwise unrelated organizations."
Password-stealing malware, also known as infostealers, can steal stored passwords and session tokens, potentially bypassing multi-factor authentication. SpyCloud found no evidence that recent Iran-linked hacks on US water providers relied on stolen passwords, instead pointing to security weaknesses like manufacturer-set default passwords in mechanical switches and physical controllers.