Full Report
SpyCloud’s study found 1,787 of the approximately 10,000 U.S. organizations had it, including one infected device that saved logins for 167 utility metering tenants. The post Another worry for water systems: infostealer exposure appeared first on CyberScoop.
Analysis Summary
# Incident Report: Widespread Infostealer Exposure in U.S. Water Sector
## Executive Summary
A research study by SpyCloud revealed significant credential exposure within the U.S. water and wastewater sector, with nearly 18% of analyzed organizations affected by infostealer malware. The compromise is highlighted by a "cascading supply chain" risk where a single infected device at a smart meter vendor exposed credentials for 167 separate utility tenants. The findings suggest a massive baseline risk for ransomware and targeted intrusions due to the availability of authenticated session cookies and VPN credentials on the dark web.
## Incident Details
- **Discovery Date:** September 22, 2026 (Report Publication)
- **Incident Date:** Ongoing/Active exposure identified in 2026
- **Affected Organization:** 1,787 U.S. Water and Wastewater organizations (including one unnamed smart meter technology provider)
- **Sector:** Critical Infrastructure / Water and Wastewater Systems (WWS)
- **Geography:** United States
## Timeline of Events
### Initial Access
- **Date/Time:** Preceding September 2026
- **Vector:** Infostealer Malware (e.g., RedLine, Racoon, or similar variants)
- **Details:** Malware typically deployed via phishing, malicious downloads, or compromised personal devices, which then harvests data from web browsers and local storage.
### Lateral Movement
- **Details:** While the report focuses on identity exposure, it notes that stolen credentials and session cookies allow attackers to bypass MFA and log into corporate emails or VPNs, facilitating silent movement through the network for reconnaissance.
### Data Exfiltration/Impact
- **Details:** Harvested data includes stolen session cookies, login credentials, and autofill information. Specifically, 258 organizations had credentials for Operational Technology (OT) or remote-access systems exposed.
### Detection & Response
- **How it was discovered:** Analysis of 10,000 organizations by SpyCloud via dark web monitoring and identity risk databases.
- **Response actions taken:** Briefing provided to CISA; initiation of responsible disclosure to affected entities.
## Attack Methodology
- **Initial Access:** Infostealer malware infection (typically via social engineering or "shadow IT").
- **Persistence:** Use of stolen session cookies to maintain authenticated access without re-triggering MFA.
- **Privilege Escalation:** Harvesting credentials stored in browsers that may have elevated administrative rights.
- **Defense Evasion:** Using legitimate credentials and session hijacking to "walk right past" security alerts.
- **Credential Access:** Extraction of saved logins and cookies from infected browser profiles.
- **Discovery:** Mapping out corporate networks while logged in as a legitimate user.
- **Lateral Movement:** Using VPN and remote-access credentials to move from IT to OT environments.
- **Collection:** Automated harvesting of browser-stored identity data.
- **Exfiltration:** Log data sold to Access Brokers or weaponized by ransomware crews.
- **Impact:** Potential for operational disruption of water treatment and metering.
## Impact Assessment
- **Financial:** High potential for future ransomware costs; costs associated with credential resets and audit.
- **Data Breach:** Exposure of credentials for 1,787 organizations; one vendor breach affected 167 tenants.
- **Operational:** Risk of unauthorized access to OT systems managing water safety and distribution.
- **Reputational:** Increased scrutiny of water sector cybersecurity following government warnings.
## Indicators of Compromise
- **Network indicators:** Logs showing successful logins from anomalous geographic locations or unrecognized devices using valid session cookies.
- **Behavioral indicators:** Excessive session hijacking attempts or unauthorized VPN access during non-business hours.
## Response Actions
- **Containment measures:** Identification of exposed accounts and invalidation of compromised sessions.
- **Eradication steps:** Cleaning infected devices (workstations/laptops) that hosted the original infostealer.
- **Recovery actions:** Sector-wide briefing via CISA to alert utilities of specific exposures.
## Lessons Learned
- **Supply Chain Vulnerability:** A single vendor’s poor endpoint security can compromise hundreds of downstream utility customers.
- **MFA Inadequacy:** Traditional MFA is insufficient against session hijacking; attackers can bypass it using stolen cookies.
- **OT/IT Convergence:** Stolen IT credentials frequently provide a pathway into sensitive OT remote-access systems.
## Recommendations
- **Implement Phishing-Resistant MFA:** Move toward hardware keys (FIDO2) to prevent session cookie theft and replay attacks.
- **Endpoint Protection:** Deploy robust EDR (Endpoint Detection and Response) to catch infostealer infections on employee and contractor devices.
- **Session Management:** Shorten session timeouts and implement device-binding for sensitive applications.
- **Dark Web Monitoring:** Regularly monitor for leaked corporate credentials to proactively reset passwords before they are weaponized by access brokers.