A recent research by cybersecurity firm SpyCloud has found that more than 1,700 US water and wastewater providers have had employee passwords and other credentials exposed by password-stealing malware. The research analysed over 66,000 publicly accessible systems linked to about 10,000 water-sector organisations registered with the US Environmental Protection Agency. This exposed a significant cybersecurity risk for water providers, as stolen credentials can provide hackers with direct access to organisational networks.
The research identified 1,787 organisations with credentials stolen by malware capable of harvesting passwords and active login sessions. At least 250 of the organisations had exposed credentials that appeared capable of providing access to operational networks and remote-access systems used to control physical infrastructure, including pumps and water flows. This could allow hackers to manipulate water supply systems, posing a risk to public health and safety.
The malware, commonly known as infostealers, can capture stored passwords and session tokens that keep users logged into online services. The stolen session tokens can allow attackers to access accounts while appearing to be legitimate users and, in some cases, bypass multi-factor authentication protections. This makes it difficult for organisations to detect and respond to cyberattacks.
A breach involving an unnamed metering technology provider was also identified, whose network had been infected with password-stealing malware. The malware reportedly harvested credentials belonging to 167 US utility companies that depended on the provider’s technology. This breach potentially gave criminals access to “a hundred otherwise unrelated organizations,” according to SpyCloud Chief Investigations Officer Jason Lancaster.
The findings come amid a series of cyberattacks targeting water providers across the United States. US authorities have linked some recent attacks to Iran-backed hackers, although SpyCloud said it found no evidence that those attacks relied on stolen passwords. Instead, the company said the attacks appeared to exploit weaknesses in industrial control equipment, including manufacturer-set default passwords.
The research highlights the risk posed by both compromised employee credentials and vulnerabilities in the systems used to operate critical water infrastructure. Stolen credentials are also traded by cybercriminals seeking access to specific organisations. This underscores the need for water providers to implement robust cybersecurity measures to protect their systems and prevent cyberattacks.
The US Environmental Protection Agency and water providers must take immediate action to address these cybersecurity risks. This includes implementing robust password management practices, multi-factor authentication, and regular security audits to detect and respond to potential cyber threats. By taking proactive steps, water providers can reduce the risk of cyberattacks and protect the public health and safety.
Key points
- Over 1,700 US water providers have had employee passwords exposed by malware.
- Stolen credentials can provide hackers with direct access to organisational networks.
- Water providers must implement robust cybersecurity measures to protect their systems.