Stolen passwords are exposing America’s water providers to hackers

Researchers say another looming threat hangs over some of America's most important critical infrastructure. New security research has found that well over a thousand U.S. water and wastewater providers are exposed to hacks due to malware that’s capable of stealing their employees’ passwords and active logged-in sessions. The findings by cybersecurity defense firm SpyCloud underscore how water providers and other critical infrastructure can be compromised with relative ease amidst a wave of hacks targeting the water supplies of dozens of communities across the United States. While password-stealing malware is not new, the research highlights how stolen passwords offer hackers an easy route to break into an organization’s network without using AI tools.
SpyCloud said it built a database of more than 66,000 public-facing systems that are registered with the U.S. Environmental Protection Agency, amounting to 10,000 organizations. The company found password-stealing malware had swiped passwords and credentials from 1,787 organizations, or nearly two in 10 providers they checked. The firm noted at least 250 organizations had credentials exposed that appeared to allow access to their operational networks and remote-access systems, which control the physical pumps and water flows. The analysis covered an unnamed metering tech provider, which had a device on its network that was infected with password-stealing malware. The malware stole reams of credentials, including passwords for 167 U.S.
Source & Attribution
This One Place News story was acquired from techcrunch.com. OPN retains the source link and provenance for newsroom review.
Filed Under
Technology & AI
