SpyCloud identified active infostealer-derived identity exposure at 1,787 of 10,000 analyzed U.S. drinking-water and wastewater organizations. The stolen data includes credentials, browser session cookies, and autofill records that could enable access to email, VPN, and other enterprise systems; hijacked authenticated sessions may also circumvent multifactor authentication. 258 organizations had exposed credentials tied to operational technology or remote-access environments, and 263 showed active phishing or business-email-compromise targeting.
A compromised endpoint at an unnamed advanced-metering vendor contained saved logins for roughly 167 utility customers, creating a concentrated third-party access risk; SpyCloud also found evidence consistent with an adversary-in-the-middle compromise involving Microsoft 365 session material at another water-technology provider. The research does not confirm intrusions or assess OT devices directly, and it does not link the exposures to recent Iran-backed water-sector attacks, which were associated with exposed OT and default passwords. SpyCloud has briefed CISA and urges utilities to revoke and rotate exposed identities and sessions while hardening internet-facing OT access.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
CISA issued an alert advising operators facing PLC-targeting activity to allowlist remote access only from known engineering laptops.
The FBI and EPA reported related activity beginning July 27, 2026, amid increased PLC targeting in the water sector.
A coordinated cyberattack affected more than 30 Minnesota community water systems on July 26 and 27. State officials identified remotely accessible operational technology as a factor in most confirmed incidents.
SpyCloud identified February 2026 telemetry at a water-treatment technology and services provider consistent with an active adversary-in-the-middle identity compromise. The data included valid Microsoft 365 authentication material associated with MFA bypass.
SpyCloud began responsible-disclosure efforts for organizations identified in its research and first briefed CISA on the findings.
SpyCloud found almost no stolen-credential exposure among the named Minnesota victims and assessed that stolen identity data was unlikely to be the primary intrusion path. It assessed that internet-exposed OT, including PLCs using default passwords, was more likely responsible.
SpyCloud found that an infected endpoint at an unnamed advanced-metering technology provider contained saved logins for approximately 167 separate utility-metering portals. The finding represented a cascading supply-chain identity exposure affecting otherwise unrelated utility organizations.
SpyCloud's analysis of 10,000 U.S. water-sector organizations identified active infostealer-derived identity exposure at 1,787 organizations. It found OT or remote-access credentials at 258 organizations and active phishing or business-email-compromise targeting at 263.
U.S. officials privately attributed a recent series of attacks on U.S. water providers to Iran-backed hackers. No threat actor was publicly attributed for the Minnesota incidents, though officials indicated a probable Iran nexus.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourcecyberscoop.com
Open sourcespycloud.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.