AI News Feed
Market watch
Cybersecurity

Stolen Passwords Expose More Than 1,700 U.S. Water Providers to Hackers, SpyCloud Says

New SpyCloud research found password-stealing malware has exposed credentials from 1,787 U.S. water and wastewater organizations, with at least 250 appearing to allow access to operational networks, as the sector faces separate Iran-linked hacks.

SpyCloud said it built a database of more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, representing 10,000 organizations. The company found that password-stealing malware had stolen passwords and credentials from 1,787 organizations, or nearly two in ten providers it checked. At least 250 organizations had credentials exposed that appeared to allow access to their operational networks and remote-access systems, which control physical pumps and water flows, SpyCloud said.

The analysis covered an unnamed metering technology provider that had a device on its network infected with password-stealing malware. The malware stole reams of credentials, including passwords for 167 U.S. utility companies that rely on the metering provider. Jason Lancaster, SpyCloud’s chief investigations officer, said in the post that the single breach handed criminals the keys to access “a hundred otherwise unrelated organizations.”

Password-stealing malware, also known as infostealers, allows hackers to steal stored passwords as well as the session tokens used to keep users logged in. Those session tokens can allow a hacker to log in as if they were the legitimate user and can often bypass multi-factor authentication systems. Hackers regularly trade stolen credentials to obtain passwords or session tokens for access to specific organizations. While such malware is not new, the research highlights how stolen passwords offer hackers an easy route to break into an organization’s network without using AI tools, TechCrunch reported.

The research comes weeks after a spate of hacks targeting water providers around the United States that the U.S. government has privately tied to Iran-backed hackers. SpyCloud said it found no evidence that those Iran-linked hacks relied on stolen passwords. In those cases, the signs point to security weaknesses, such as manufacturer-set default passwords, in the mechanical switches and physical controllers used by critical infrastructure, SpyCloud said, echoing earlier findings from the U.S. cybersecurity agency CISA.

SpyCloud researchers said stolen passwords are a major source of access to “whoever wants to buy or find it,” in parallel with the known security risks in critical infrastructure technology. Lancaster said the water sector “has to hold both stories at once.”