supply-chaintrade-pressNewsThe Broadside2 min read

Infostealer Logs Expose Credentials at 18% of Water Utilities

One infected vendor device held saved logins for 167 utility tenants: a single infostealer infection cascading through the sector's supply chain.


TL;DR

SpyCloud analyzed roughly 10,000 EPA-registered water systems and found active infostealer exposure at 1,787 of them, with 258 carrying credentials to OT or remote-access systems. The sharpest finding: one infected device at an unnamed smart-meter vendor contained saved logins for roughly 167 utility tenants. The study measures identity exposure, not confirmed intrusion. Larger operators are overrepresented; small utilities, the bulk of America's 50,000 water systems, are largely absent.

The water sector has spent the summer of 2026 staring at exposed programmable logic controllers. Suspected Iranian affiliates have locked operators out of PLCs across at least a dozen states, triggering boil-water notices and forcing manual operations. CISA's response has been a drumbeat of advisories telling utilities one thing: disconnect controllers from the public internet.

SpyCloud's study, published Tuesday, surfaces a parallel threat vector, one that doesn't need an internet-facing PLC at all. Infostealer malware silently harvests saved credentials, session cookies, and autofill data from infected devices. Those logs circulate on criminal marketplaces where access brokers sell them to ransomware crews.

The attacker isn't guessing passwords. They're walking through the front door with a valid session token, often bypassing MFA entirely by hijacking an already-authenticated session. Jason Lancaster, SpyCloud's chief investigations officer, put it bluntly: "Infostealer exposure means the attacker isn't guessing anymore, they've got legitimate points of entry."

The supply-chain finding is the study's sharpest result. One unnamed smart-meter technology provider had a single infected device whose logs contained saved logins for roughly 167 different utility metering tenants. One breach surface, nearly 170 downstream doors. SpyCloud has begun briefing CISA and is conducting responsible disclosure with the affected organizations.

The study carries limitations. Larger operators are overrepresented in the data; small utilities, which make up the vast majority of America's roughly 50,000 community water systems, are largely absent. The research didn't examine OT devices directly, so the 258 organizations with OT or remote-access credentials in infostealer logs likely represent a floor, not a ceiling. And this measures identity exposure, not confirmed intrusion. Some of those credentials may be expired, rotated, or tied to accounts with limited access.

Your vendor's infected laptop is your problem

For a water utility security lead, the study sharpens a question the PLC advisories didn't answer. It's not enough to disconnect controllers from the internet. You also need to know whether your people, or your vendors' people, have had credentials harvested from a personal device, a contractor laptop, or a home machine that once auto-saved the VPN password. SpyCloud's disclosure process may land on your desk this week.


Published ·Deep Fathom