Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

US water providers exposed to hacks by stolen employee passwords

New security research indicates that over a thousand US water and wastewater providers are vulnerable to cyberattacks due to malware stealing employee passwords and active login sessions.

  • Cybersecurity firm SpyCloud found that 1,787 US water organisations had credentials stolen by password-stealing malware.
  • At least 250 organisations had exposed credentials that appeared to allow access to their operational networks and remote-access systems.
  • A single breach at an unnamed metering tech provider exposed passwords for 167 US utility companies.

New security research has revealed that more than a thousand US water and wastewater providers are exposed to hacks. This vulnerability stems from malware capable of stealing employees' passwords and active logged-in sessions.

The findings by cybersecurity defence firm SpyCloud highlight how critical infrastructure, including water providers, can be compromised. The firm analysed over 66,000 public-facing systems registered with the US Environmental Protection Agency, representing 10,000 organisations.

SpyCloud discovered that password-stealing malware had swiped credentials from 1,787 organisations, nearly two in ten of those checked. At least 250 of these organisations had exposed credentials that appeared to allow access to their operational networks and remote-access systems, which control physical pumps and water flows.

One incident involved an unnamed metering tech provider whose network device was infected with password-stealing malware. This breach stole credentials, including passwords for 167 US utility companies reliant on that provider. Jason Lancaster, SpyCloud's chief investigations officer, stated this single breach provided criminals with access to "a hundred otherwise unrelated organizations."

Password-stealing malware, also known as infostealers, can steal stored passwords and session tokens, potentially bypassing multi-factor authentication. SpyCloud found no evidence that recent Iran-linked hacks on US water providers relied on stolen passwords, instead pointing to security weaknesses like manufacturer-set default passwords in mechanical switches and physical controllers.

Why this matters: The research underscores how easily critical infrastructure can be compromised, posing a significant threat to essential services.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.