< Back to all clusters
[TECHNOLOGY] · United States · 3 sources

started · updated

U.S. water utilities face rising cyberattacks and credential theft

Cybersecurity threats against United States water and wastewater providers are escalating, involving both direct manipulation of operational technology and widespread credential theft. In late August, foreign hackers breached the operational technology systems of two private water utilities in Colorado. The attackers altered equipment settings, disabled remote access and alarms, and changed pumping cycles. While officials stated that water quality and public safety were not affected, the incidents highlight a shift toward active probing of critical infrastructure.

Complementary research from cybersecurity firm SpyCloud indicates that over 1,700 organizations, including nearly 20% of surveyed providers, have had credentials compromised by password-stealing malware. The research found that at least 250 organizations had exposed credentials that could allow access to operational networks and remote-access systems controlling physical pumps and water flows.

In one instance, malware infecting a metering technology provider allowed criminals to access credentials for 167 utility companies. These ‘infostealers’ can capture session tokens, which may allow hackers to bypass multi-factor authentication by mimicking legitimate users. CISA has previously noted that more than 100 internet-exposed water systems were targeted in July, specifically focusing on programmable logic controllers.

Entities

CISA · Jared Polis · SpyCloud · U.S. Environmental Protection Agency