SpyCloud studied 10,000 US water and wastewater organizations and found active infostealer exposure at 1,787 of them, roughly a fifth.
Building that sample took 66,845 EPA-registered systems, all mapped by internet domain before the analysis narrowed to 10,000. The report’s timing is pointed: the sector has absorbed months of attacks that US officials suspect trace back to Iran.
One laptop, 167 utility customers
The finding that stood out involved one compromised laptop at an unnamed smart meter technology vendor. Credentials stored on that single machine led to roughly 167 separate utility metering tenants, an effect SpyCloud calls cascading supply chain exposure.
Jason Lancaster, the firm’s chief investigations officer, argues that a stolen-log hit removes the guesswork – the intruder arrives holding genuine entry points. Session cookies, credentials and autofill data are what his investigators find inside those logs. Reusing an already-trusted session reportedly defeats multifactor authentication, opens corporate email or a VPN without an alert, and lets an attacker map the network quietly for weeks.
Reading the numbers carefully
Scope deserves attention here. Operational technology was not what SpyCloud measured, and no figure in the report should be read as evidence about specific OT equipment. It did record that 258 of the exposed organizations held credentials for OT or remote-access systems. Small utilities were also underrepresented; the data skewed toward larger operators and the vendor supply chain.
These numbers describe identity exposure, not a confirmed intrusion. Disclosure has begun, starting with CISA.
