Cyberscoop

Another worry for water systems: infostealer exposure


Nearly two of every 10 U.S. water and wastewater organizations have identity data actively exposed from infostealers harvesting their credentials, according to research published Tuesday.

The study from identity risk firm SpyCloud follows months of reports about a wave of cyberattacks hitting targets in the sector, which U.S. government officials suspect are tied to Iran.

The company built a database of 66,845 Environmental Protection Agency-registered systems, examined internet domains and ultimately analyzed 10,000 organizations, finding that 1,787 showed active infostealer exposure.

In one case, a single infected device at a smart meter technology provider that SpyCloud didn’t name contained saved logins linked to roughly 167 different U.S. utility metering tenants — meaning that one exposure opened the door to many more. 

That “cascading supply chain exposure” was one of the biggest findings of the report that SpyCloud shared exclusively with CyberScoop, said Jason Lancaster, chief investigations officer at the cyber firm, along with the quantitative approach” to measure exposure overall.

“We talk about it a lot,” Lancaster said of the exponential risk that one exposure can present. “There’s examples here and there, but that was a standout example of, here’s a tangible thing that is an exposure right now.”

Generally, “Infostealer exposure means the attacker isn’t guessing anymore, they’ve got legitimate points of entry,” Lancaster said. “In the investigations I’ve worked, that log data usually contains stolen session cookies, credentials, and autofill info pulled straight off the infected device. That’s enough to walk right past [multifactor authentication] by hijacking an already-authenticated session, log into corporate email or VPNs without raising a single alert, and sit there quietly for weeks while they map out the network.”

Still, the study had limitations. It doesn’t address what apparently led to the cyberattacks that unfolded in Minnesota and elsewhere this summer: internet-exposed programmable logic controllers.

It’s “important to note that our research did not focus on OT devices which run the most critical processes within these utilities, and any exposure we cite herein should not be interpreted as exposure of specific OT devices,” the report said. It did, however, find that 258 of the 1,787 organizations with active infostealer exposure carried credentials to operational technology or remote-access systems.

Some of the report’s conclusions were about the limitations of the data itself.

“Exposure concentrated in larger operators and in the vendor supply chain; small utilities were largely underrepresented,” SpyCloud said. “That’s a pattern in the data, not a claim that every water system nationwide carries this risk — and it measures identity exposure, not confirmed intrusion.”

It’s the first study of its kind that SpyCloud has done for a specific industry, so the company doesn’t have comparisons to other industries, Lancaster said. SpyCloud has begun a responsible disclosure process for those affected within its report, he said, beginning with a briefing for the Cybersecurity and Infrastructure Security Agency.

“It’s important to remember, infostealer logs aren’t the end of an incident — they are often the beginning,” Lancaster said. “Access brokers sell these logs specifically because ransomware crews and other fraudsters want exactly this kind of entry point. So, the real question isn’t whether the exposure is dangerous. It’s how much time you have before someone weaponizes that stolen data against you.”

Written by Tim Starks

Tim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he’s covered cybersecurity since 2003. Email Tim here: tim.starks@cyberscoop.com.



Source link