AI

Compromised Passwords Leave U.S. Water Utilities Vulnerable to Cyber Attacks

Recent cybersecurity research has revealed that over a thousand water and wastewater service providers in the United States are vulnerable to cyberattacks, primarily due to malware that can capture employees’ passwords and active session information.

The investigation conducted by cybersecurity firm SpyCloud emphasizes the ease with which hackers can target water providers and similar critical infrastructure, amid a troubling trend of attacks on water supply systems across various U.S. communities.

Although malware designed to steal passwords is not a novel threat, this research illustrates that hijacked credentials provide an uncomplicated pathway for cybercriminals to infiltrate an organization’s network without the need for advanced AI technologies.

SpyCloud compiled a database containing information on over 66,000 publicly accessible systems registered with the U.S. Environmental Protection Agency, covering around 10,000 organizations. Their analysis revealed that password-stealing malware had captured credentials from 1,787 organizations, representing nearly 20% of those examined. Notably, at least 250 of these organizations had exposed credentials that could grant access to vital operational networks and remote access systems managing water pumps and flow controls.

The assessment included a metering technology provider that had a device within its network compromised by password-stealing malware, resulting in the theft of credentials for 167 utility companies dependent on its technology.

Jason Lancaster, SpyCloud’s chief investigations officer, remarked that this single breach provided criminals with access to “a hundred otherwise unrelated organizations.”

Known as infostealers, password-stealing malware enables hackers to extract stored passwords and session tokens that maintain user logins. These tokens can enable an attacker to impersonate a legitimate user, often bypassing multi-factor authentication measures. Cybercriminals frequently trade stolen credentials to secure access to specific entities.

This research follows a recent series of cyberattacks on water providers in the U.S., which have been privately associated with hackers supported by Iran. SpyCloud stated that there was no indication that these Iran-linked attacks utilized stolen passwords. Instead, the issues were related to security vulnerabilities, including factory preset passwords on various mechanical switches and controllers crucial for the infrastructure, echoing findings from the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Researchers emphasize that stolen passwords are a significant means of access for anyone seeking to exploit or acquire them, highlighting the ongoing security challenges faced by critical infrastructure technologies. According to Lancaster, the water sector needs to reconcile both narratives simultaneously.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button