🚨Malware Hits 1,787 Water Providers, Stolen Passwords at Risk
1,787 water providers hit by password-stealing malware
TL;DR
SpyCloud found password-stealing malware had compromised over 1,787 water providers, exposing critical passwords and credentials. This breach could allow hackers to bypass MFA and access operational networks.
Password-stealing malware has compromised over 1,787 U.S. water and wastewater providers, exposing critical passwords and credentials. This breach could allow hackers to bypass multi-factor authentication and access operational networks, posing a significant threat to critical infrastructure. SpyCloud's research highlights the vulnerability of default passwords and the ease with which hackers can gain unauthorized access to networks. The malware, capable of stealing active sessions, has exposed credentials for 167 U.S. utility companies, potentially impacting a hundred unrelated organizations.

Key Points
SpyCloud's research found malware compromised 1,787 U.S. water providers, exposing critical passwords and credentials.
The malware stole credentials from 1,787 organizations, nearly two in ten providers checked by SpyCloud.
Hackers can use stolen passwords to bypass multi-factor authentication and access operational networks.
At least 250 organizations had credentials exposed that allow access to their operational networks and remote-access systems.
The research highlights the vulnerability of default passwords and the ease of gaining unauthorized access to networks.
Why It Matters
If you're managing critical infrastructure, the exposure of 1,787 water providers' passwords and credentials is a wake-up call. Default passwords and session token vulnerabilities can allow hackers to bypass MFA and access operational networks, impacting a hundred unrelated organizations. This breach underscores the need for robust security measures and regular password audits.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,491 builders reading daily.