Foreign hackers breached two Colorado water utilities last month, Gov. Polis’ office says
- Research published Tuesday shows nearly two in ten United States water and wastewater organizations have identity data actively exposed to password-stealing malware, according to cybersecurity firm SpyCloud.
- Infostealer malware harvests credentials and session tokens, allowing attackers to bypass multifactor authentication and access corporate email or VPNs without triggering alerts, explained SpyCloud chief investigations officer Jason Lancaster.
- Analyzing 10,000 organizations, the firm found 1,787 with active exposure, including at least 250 with credentials for operational networks and one metering provider breach exposing logins for 167 separate utility tenants.
- Officials revealed Tuesday that foreign hackers breached two small water providers in Colorado last month, altering pumping cycles and disabling alarms, though treatment processes and water quality remained unaffected.
- According to officials, the findings emerge amid broader risks to critical infrastructure, including recent incidents linked to Iranian-backed actors, though SpyCloud noted its research did not focus on operational technology devices.
13 Articles
13 Articles
Stolen Credentials Open New Front in Assault on U.S. Water Systems
SpyCloud research reveals 1,787 U.S. water organizations exposed via infostealer malware, including operational credentials at 258 sites. A single vendor device leaked access for 167 utilities. The findings add a new dimension to recent Iran-linked attacks on water infrastructure that exploited weak defaults and exposed PLCs.
Another worry for water systems: infostealer exposure
An exclusive SpyCloud report reveals nearly 1,800 EPA-registered water systems and utilities face active infostealer malware exposure, highlighting widespread supply chain risks.
Foreign hackers breached two Colorado water utilities
Two small, privately owned Colorado water utilities were breached by foreign hackers in August, according to the governor’s office. The office says it remains unclear what foreign actors may have been involved in the breach.
Coverage Details
Bias Distribution
- 86% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium












