VYPR
breachPublished Sep 22, 2026· 1 source

Infostealer Exposure Poses Significant Risk to U.S. Water Systems

A new study reveals that nearly 20% of U.S. water and wastewater organizations have identity data exposed through infostealers, creating pathways for attackers to bypass MFA and access critical systems.

A recent study by identity risk firm SpyCloud has uncovered a significant cybersecurity vulnerability within the U.S. water and wastewater sector, with 1,787 organizations found to have identity data exposed via infostealers. This exposure means that credentials, session cookies, and autofill information stolen from infected devices are readily available to attackers, providing them with legitimate points of entry into corporate networks.

The research, which analyzed data from 10,000 organizations registered with the Environmental Protection Agency, highlights a concerning trend that aligns with recent government warnings about cyberattacks targeting critical infrastructure, potentially linked to Iran. The implications of this widespread credential exposure are severe, as attackers can leverage stolen session cookies to bypass multi-factor authentication (MFA) and gain access to corporate email or VPNs without triggering alerts. This allows threat actors to operate undetected for extended periods, mapping out networks before launching more sophisticated attacks.

One particularly alarming finding was the discovery of a single infected device at a smart meter technology provider that contained saved logins linked to approximately 167 different U.S. utility metering tenants. This instance exemplifies the cascading supply chain risk, where a single point of compromise can lead to widespread access across multiple organizations, underscoring the interconnected nature of the sector's digital infrastructure.

While the study did not focus on operational technology (OT) devices, which control critical processes, it did identify that 258 of the affected organizations also had credentials for OT or remote-access systems exposed. This suggests a potential pathway for attackers to move from IT systems into more sensitive operational environments, posing a direct threat to the physical infrastructure managed by these utilities.

SpyCloud emphasized that the data reflects identity exposure, not confirmed intrusions, and noted that larger operators and the vendor supply chain were more represented in the findings, with smaller utilities being less represented. This pattern suggests that while the measured risk is significant, the actual exposure across the entire sector could be even broader.

The firm has initiated a responsible disclosure process with affected entities and has briefed the Cybersecurity and Infrastructure Security Agency (CISA) on its findings. SpyCloud's chief investigations officer, Jason Lancaster, stressed that infostealer logs are often just the beginning of an incident, as they are actively traded on the dark web by access brokers seeking entry points for ransomware crews and other malicious actors.

The findings serve as a stark reminder of the persistent threats facing critical infrastructure. The ease with which attackers can obtain legitimate credentials and bypass security measures like MFA highlights the urgent need for enhanced identity security practices, regular credential hygiene, and robust monitoring to detect and respond to the weaponization of stolen data.

Synthesized by Vypr AI
Infostealer Exposure Poses Significant Risk to U.S. Water Systems · VYPR