Executive Summary
In December 2024, cybersecurity firm SpyCloud published research revealing that nearly 20% of U.S. water and wastewater organizations have identity data actively exposed through infostealer malware. The study analyzed 10,000 EPA-registered water systems and found 1,787 organizations with active credential exposure, including a critical supply chain incident where a single compromised device at a smart meter technology provider exposed login credentials for approximately 167 different utility companies. Attackers leveraging these stolen credentials can bypass multi-factor authentication through session hijacking and gain persistent access to corporate networks.
This research comes amid heightened scrutiny of critical infrastructure security following multiple cyberattacks on water systems throughout 2024, with U.S. officials attributing many incidents to Iranian threat actors targeting operational technology systems.
Why This Matters Now
Water utilities face escalating nation-state threats while managing aging infrastructure and limited cybersecurity resources, making credential theft a critical attack vector for accessing industrial control systems that could disrupt public health and safety services.
Attack Path Analysis
Infostealers compromised devices at water utility organizations and vendor systems, harvesting credentials and session cookies. Attackers used stolen credentials to bypass MFA via session hijacking and access corporate email/VPN systems. From initial access points, attackers performed network reconnaissance and moved laterally across utility networks. Command and control was established through legitimate channels using hijacked sessions. Sensitive operational data and credentials were exfiltrated to external systems. Supply chain exposure created cascading impact across multiple utility organizations through shared vendor access.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Infostealers infected devices at water utility organizations and vendor systems, harvesting stored credentials, session cookies, and autofill data from browsers and applications
MITRE ATT&CK® Techniques
Credentials from Password Stores
Steal Web Session Cookie
Valid Accounts
Phishing
Input Capture
Acquire Infrastructure: Domains
Trusted Relationship
Use Alternate Authentication Material: Web Session Cookie
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: ID.AM-2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
Digital Operational Resilience Act (DORA) – Third-party Risk Management
Control ID: Article 28
PCI DSS 4.0 – Strong Cryptography for Authentication
Control ID: 8.2.1
ISO 27001:2022 – Information Security in Supplier Relationships
Control ID: A.5.19
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Water and wastewater systems face critical infostealer exposure with 18% showing active credential harvesting, enabling attackers to bypass MFA through session hijacking and access operational technology systems.
Government Administration
EPA-registered water systems under government oversight experience cascading supply chain exposures through infostealers, compromising regulatory compliance and creating vulnerabilities across multiple municipal utility networks simultaneously.
Computer Software/Engineering
Smart meter technology providers represent high-value targets where single infostealer infections expose credentials for 167+ utility tenants, demonstrating critical supply chain vulnerabilities in utility software systems.
Environmental Services
Environmental water management organizations face identity-based attacks through infostealer malware, with 258 exposed entities having credentials to operational technology systems critical for water treatment processes.
Sources
- Another worry for water systems: infostealer exposurehttps://cyberscoop.com/spycloud-study-water-utilities-infostealer-exposure/Verified
- SpyCloud Identity Exposure Report - Water Utilitieshttps://spycloud.com/resource/identity-exposure-report-water-utilities/Verified
- CISA Water and Wastewater Systems Cybersecurityhttps://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-systems-sectorVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this water utility attack through microsegmentation and identity-aware access controls. The attacker's lateral movement and supply chain propagation would be significantly reduced through workload isolation and controlled network paths.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security fabric could likely limit the scope of credential harvesting by constraining application access to segmented environments and reducing the breadth of systems accessible from initially compromised endpoints
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain session hijacking impact by limiting authenticated session scope to specific network segments and reducing the breadth of systems accessible through compromised sessions
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement by blocking unauthorized inter-system communication and reducing attacker ability to traverse from corporate networks to operational technology environments
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls could likely detect anomalous session behavior patterns and constrain persistent access by identifying unusual communication flows across utility cloud and hybrid environments
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely constrain data exfiltration by blocking unauthorized outbound transfers and reducing the volume of operational data accessible for extraction from utility networks
While vendor compromise might still occur, the cascading impact across utility tenants would likely be significantly reduced through isolated access boundaries and constrained credential scope across segmented environments
Impact at a Glance
Affected Business Functions
- Water Treatment Operations
- Distribution System Management
- Customer Billing Systems
- Regulatory Compliance Reporting
Estimated downtime: N/A
Estimated loss: N/A
Credentials and authentication data for 1,787 water and wastewater organizations exposed through infostealer malware. One smart meter technology provider had saved logins for approximately 167 utility metering tenants. 258 organizations had credentials to operational technology or remote-access systems compromised. Exposed data includes session cookies, login credentials, and autofill information that could bypass multifactor authentication.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between utility networks and limit access based on least privilege principles
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts from operational technology environments
- • Enable Multicloud Visibility & Control to monitor for anomalous interactions and suspicious session activity across hybrid infrastructure
- • Establish Threat Detection & Anomaly Response capabilities to identify infostealer infections and compromised session behavior patterns
- • Implement Encrypted Traffic (HPE) controls to protect sensitive operational data in transit and prevent credential harvesting from network communications



