Skip to content

Security1 publisher2 min readPublished

One infected device at a smart meter vendor held logins to 167 utility metering tenants

SpyCloud measured stolen-credential exposure across 10,000 EPA-registered water and wastewater organizations and found it at nearly one in five, with the sharpest single case sitting on a supplier's machine.

The Watch · Security desk

Illustration accompanying One infected device at a smart meter vendor held logins to 167 utility metering tenants

What happened

  • SpyCloud started from a database of 66,845 EPA-registered systems, narrowed it by internet domain, analyzed 10,000 water and wastewater organizations, and found 1,787 with active infostealer exposure.
  • One infected device at a smart meter technology provider held saved logins tied to roughly 167 different U.S. utility metering tenants, the largest single case in the data.
  • SpyCloud, which published the research Tuesday and shared it with CyberScoop, has started a disclosure process with the affected organizations, beginning with a briefing for CISA.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure About 167 metering tenants had their access decided by one supplier's endpoint hygiene, and none of their own perimeter controls had a vote in it.
  • capability Stolen session cookies let an intruder resume a session that has already passed multifactor authentication, so the login generates no failed-auth trail for a defender to spot.
  • contradiction An operator choosing between rotating vendor credentials and pulling controllers off the internet gets no ranking from this report: it quantifies the first and explicitly disclaims the second.
  • constraint Because small utilities were underrepresented in the sample, a small system cannot treat the one-in-five figure as its own planning number.

A stealer log is the contents of one machine at one moment: saved browser credentials, autofill fields, and whatever session cookies were live when the malware ran. Jason Lancaster, SpyCloud's chief investigations officer, said that content changes what an intruder has to do first. "Infostealer exposure means the attacker isn't guessing anymore, they've got legitimate points of entry," he said [7]. He said the log data is enough to walk right past multifactor authentication by hijacking an already-authenticated session, log into corporate email or VPNs without raising a single alert, and sit there quietly for weeks while mapping out the network [8].

Of the 1,787 organizations with active exposure, 258 had credentials to operational technology or remote-access systems in their logs [11]. That is 14.4 percent of the exposed group and 2.6 percent of the 10,000 organizations analyzed [2][3]. The 10,000 were drawn from a starting database of 66,845 EPA-registered systems, about 15 percent of it [4].

The metering case is one device. Lancaster called it "cascading supply chain exposure" and one of the report's biggest findings [4], and said: "There's examples here and there, but that was a standout example of, here's a tangible thing that is an exposure right now" [6]. SpyCloud did not name the provider [3].

The study cannot rank credential theft against exposed controllers, because it did not look at controllers. "Our research did not focus on OT devices which run the most critical processes within these utilities, and any exposure we cite herein should not be interpreted as exposure of specific OT devices," the report said [10]. Internet-exposed programmable logic controllers are what apparently led to the attacks in Minnesota and elsewhere this summer [9], part of a wave of intrusions in the sector that U.S. government officials suspect are tied to Iran [17]. SpyCloud also flagged its own sampling: exposure "concentrated in larger operators and in the vendor supply chain; small utilities were largely underrepresented" [12], and the figure "measures identity exposure, not confirmed intrusion" [13].

This is the first study SpyCloud has run on a single industry, so it has no exposure rate from another sector to compare the water number against, Lancaster said [14]. The company has started notifying the organizations named in the data, beginning with a briefing for the Cybersecurity and Infrastructure Security Agency [15]. On timing, Lancaster said: "Access brokers sell these logs specifically because ransomware crews and other fraudsters want exactly this kind of entry point. So, the real question isn't whether the exposure is dangerous. It's how much time you have before someone weaponizes that stolen data against you" [16].

What to watch

  • Whether SpyCloud's CISA briefing turns into named notifications to the affected utilities and to the unnamed metering provider.
  • Whether any confirmed intrusion at a U.S. water utility is traced back to a stealer log, which would move the finding from identity exposure to incident.
  • Whether SpyCloud repeats the measurement on a second sector, producing the baseline the water figure currently lacks.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories