Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, News

Infostealer Malware Is Quietly Exposing the Passwords Behind North America’s Water Systems

What Happened

Researchers at SpyCloud examined roughly 10,000 EPA-registered water and wastewater organizations and found active infostealer malware exposure at 1,787 of them, close to one in five. Infostealer malware harvests far more than a password. It pulls session cookies, saved logins, and autofill data straight off an infected device, giving an attacker a way to bypass multi-factor authentication and walk into corporate email or VPN sessions without triggering a login alert.

Of the affected organizations, 258 had credentials tied directly to operational technology or remote-access tools such as TeamViewer, the systems sitting closest to the equipment controlling treatment and distribution. One infected device belonging to a smart meter technology vendor held saved logins for around 167 separate utility clients, a single point of failure researchers describe as cascading supply chain exposure. Read the full findings from CyberScoop.

Why This Matters for Canadian Organizations

The study covers US utilities, and no Canadian organization appears in the published findings. The exposure pattern behind it does not respect a border. Canadian water and wastewater systems rely on the same class of vendors, the same remote monitoring tools, and often the same smart metering technology as their US counterparts, and a compromised vendor laptop does not check a client’s postal code before leaking its saved sessions.

Canada operates roughly 3,000 drinking water systems and 3,500 wastewater systems, the large majority run by small municipal teams without a dedicated security operations center. Under Bill C-26, operators of designated critical systems face incident reporting duties to the Canadian Centre for Cyber Security, and a credential-driven intrusion traced back to an infected contractor laptop counts, whether or not the compromise involved a direct attack on utility infrastructure.

What to Do

Water utilities and their vendors should inventory every remote-access tool touching operational systems and confirm multi-factor authentication rejects a replayed session cookie, not only a stolen password. Treat every third-party vendor with system access, especially metering and monitoring providers, as part of the attack surface, and ask directly whether they scan employee devices for infostealer infection. Rotate credentials for any account with confirmed exposure, and log remote-access sessions closely enough to catch one starting from an unfamiliar device.

Track related critical infrastructure coverage in our News section and technical breakdowns in TechTalk.

Enjoy this article? Don’t forget to share.