Back Cyberscoop Another worry for water systems: infostealer exposure
Nearly two of every 10 U.S. water and wastewater organizations have identity data actively exposed from infostealers harvesting their credentials, according to research published Tuesday.
The study from identity risk firm SpyCloud follows months of reports a wave of cyberattacks hitting targets in the sector , which U.S. government officials suspect are tied to Iran.
The company built a database of 66,845 Environmental Protection Agency-registered systems, examined internet domains and ultimately analyzed 10,000 organizations, finding that 1,787 showed active infostealer exposure.
In one case, a single infected device at a smart meter technology provider that SpyCloud didn’t name contained saved logins linked to roughly 167 different U.S. utility metering tenants — meaning that one exposure opened the door to many more.
That “cascading supply chain exposure” was one of the biggest findings of the report that SpyCloud shared exclusively with CyberScoop, said Jason Lancaster, chief investigations officer at the cyber firm, along with the quantitative approach” to measure exposure overall.
“We talk it a lot,” Lancaster said of the exponential risk that one exposure can present. “There’s examples here and there, but that was a standout example of, here’s a tangible thing that is an exposure right now.”
Generally, “Infostealer exposure means the attacker isn’t guessing anymore, they’ve got legitimate points of entry,” Lancaster said. “In the investigations I’ve worked, that log data usually contains stolen session cookies, credentials, and autofill info pulled straight off the infected device. That’s enough to walk right past [multifactor authentication] by hijacking an already-authenticated session, log into corporate email or VPNs without raising a single alert, and sit there quietly for weeks while they map out the network.”
Still, the study had limitations. It doesn’t address what apparently led to the cyberattacks that unfolded in Minnesota and elsewhere this summer: internet-exposed programmable logic controllers .
It’s “important to note that our research did not focus on OT devices which run the most critical processes within these utilities, and any exposure we cite herein should not be interpreted as exposure of specific OT devices,” the report said. It did, however, find that 258 of the 1,787 organizations with active infostealer exposure carried credentials to operational technology or remote-access systems.
Some of the report’s conclusions were the limitations of the data itself.
“Exposure concentrated in larger operators and in the vendor supply chain; small utilities were largely underrepresented,” SpyCloud said. “That’s a pattern in the data, not a claim that every water system nationwide carries this risk — and it measures identity exposure, not confirmed intrusion.”
It’s the first study of its kind that SpyCloud has done for a specific industry, so the company doesn’t have comparisons to other industries, Lancaster said. SpyCloud has begun a responsible disclosure process for those affected within its report, he said, beginning with a briefing for the Cybersecurity and Infrastructure Security Agency.
“It’s important to remember, infostealer logs aren’t the end of an incident — they are often the beginning,” Lancaster said. “Access brokers sell these logs specifically because ransomware crews and other fraudsters want exactly this kind of entry point. So, the real question isn’t whether the exposure is dangerous. It’s how much time you have before someone weaponizes that stolen data against you.”
What the Section 702 lapse means for cybersecurity
ClickFix and the social engineering of routine
AI-adaptable security platforms are critical for autonomous decision-making
Defending in the middle of the vulnpocalypse
International security agencies warn North Korean hackers exploiting job seekers to steal crypto, data
The AI hacking apocalypse is not inevitable
CISA promotes a fresh way to deter cyberattackers: Lie to them
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
What’s for CISA's CDM program that gives cybersecurity tools to federal agencies
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The G7 tells industry to hurry up and prep for post-quantum encryption
Cisco alerts customers to second actively exploited zero-day in as many days
Authorities seize popular, long-running DDoS-for-hire service domains
Cisco warns customers of actively exploited zero-day in email gateways
Five alleged leaders of Black Axe’s operations in South Africa extradited to US
Supreme Court denies Trump request to allow USPS mail ballot changes
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
Hawley probes OpenAI over Hugging Face breach
Governments ‘buying time’ in race between innovation, security, national cyber director says
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
