Malware collected logins from 1,787 US water organizations, SpyCloud says

The Cool Down

SpyCloud says credential-stealing malware collected employee logins from 1,787 US water and wastewater organizations; credentials from at least 250 appeared able to reach operational networks and remote-access tools. The report does not show any utility was compromised.

SpyCloud reviewed more than 66,000 outward-facing systems registered with the US Environmental Protection Agency in its analysis of roughly 10,000 organizations. Separately, it found that one infected device at an unnamed metering-technology provider held passwords tied to 167 US utilities that used the vendor.

Infostealers can also capture session tokens, potentially letting hackers impersonate users and, in some cases, bypass multi-factor authentication. TechCrunch reported that the US government privately linked recent water-provider breaches to Iran-backed hackers; SpyCloud found no sign stolen passwords drove those attacks, which appeared instead to involve other weaknesses, including factory-default passwords on mechanical switches and physical controllers.

#US-water-utility-credential-theft #SpyCloud-water-utility-report
Share