The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In December 2024, cybersecurity firm SpyCloud published research revealing that nearly 20% of U.S. water and wastewater organizations have identity data actively exposed through infostealer malware. The study analyzed 10,000 EPA-registered water systems and found 1,787 organizations with active credential exposure, including a critical supply chain incident where a single compromised device at a smart meter technology provider exposed login credentials for approximately 167 different utility companies. Attackers leveraging these stolen credentials can bypass multi-factor authentication through session hijacking and gain persistent access to corporate networks.

This research comes amid heightened scrutiny of critical infrastructure security following multiple cyberattacks on water systems throughout 2024, with U.S. officials attributing many incidents to Iranian threat actors targeting operational technology systems.

Why This Matters Now

Water utilities face escalating nation-state threats while managing aging infrastructure and limited cybersecurity resources, making credential theft a critical attack vector for accessing industrial control systems that could disrupt public health and safety services.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Infostealers capture session cookies and authentication tokens from infected devices, allowing attackers to hijack already-authenticated sessions and access systems without triggering MFA prompts.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this water utility attack through microsegmentation and identity-aware access controls. The attacker's lateral movement and supply chain propagation would be significantly reduced through workload isolation and controlled network paths.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-native security fabric could likely limit the scope of credential harvesting by constraining application access to segmented environments and reducing the breadth of systems accessible from initially compromised endpoints

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely constrain session hijacking impact by limiting authenticated session scope to specific network segments and reducing the breadth of systems accessible through compromised sessions

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely constrain lateral movement by blocking unauthorized inter-system communication and reducing attacker ability to traverse from corporate networks to operational technology environments

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls could likely detect anomalous session behavior patterns and constrain persistent access by identifying unusual communication flows across utility cloud and hybrid environments

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely constrain data exfiltration by blocking unauthorized outbound transfers and reducing the volume of operational data accessible for extraction from utility networks

Impact (Mitigations)

While vendor compromise might still occur, the cascading impact across utility tenants would likely be significantly reduced through isolated access boundaries and constrained credential scope across segmented environments

Impact at a Glance

Affected Business Functions

  • Water Treatment Operations
  • Distribution System Management
  • Customer Billing Systems
  • Regulatory Compliance Reporting
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Credentials and authentication data for 1,787 water and wastewater organizations exposed through infostealer malware. One smart meter technology provider had saved logins for approximately 167 utility metering tenants. 258 organizations had credentials to operational technology or remote-access systems compromised. Exposed data includes session cookies, login credentials, and autofill information that could bypass multifactor authentication.

Recommended Actions

  • • Implement Zero Trust Segmentation to prevent lateral movement between utility networks and limit access based on least privilege principles
  • • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts from operational technology environments
  • • Enable Multicloud Visibility & Control to monitor for anomalous interactions and suspicious session activity across hybrid infrastructure
  • • Establish Threat Detection & Anomaly Response capabilities to identify infostealer infections and compromised session behavior patterns
  • • Implement Encrypted Traffic (HPE) controls to protect sensitive operational data in transit and prevent credential harvesting from network communications

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image