"Infostealer exposure means the attacker isn’t guessing anymore, they’ve got legitimate points of entry," said Jason Lancaster, chief investigations officer at SpyCloud.
SpyCloud’s industry-specific study: scope and headline figures
Identity-risk firm SpyCloud built a database of 66,845 Environmental Protection Agency-registered systems, examined internet domains, and ultimately analyzed 10,000 water and wastewater organizations. The company found 1,787 of those organizations showed active infostealer exposure — nearly two of every 10 organizations in the sample — according to the report shared exclusively with CyberScoop.
SpyCloud characterized this as a first-of-its-kind study focused on a single industry and noted that it measures identity exposure, not confirmed intrusion. The company also said exposure in the data concentrated in larger operators and in the vendor supply chain, while small utilities were largely underrepresented.
Single infected device, wide access: the smart meter example
The report includes a striking example that illustrates the risk SpyCloud labeled "cascading supply chain exposure." A single infected device at a smart meter technology provider — the company wasn’t named in the report — contained saved logins linked to roughly 167 different U.S. utility metering tenants. SpyCloud described that instance as a standout example of exponential risk: one exposure creating many more.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadWhat infostealer logs contain and how they are used, per investigations
Jason Lancaster described the typical contents of infostealer logs and their operational impact. "In the investigations I’ve worked, that log data usually contains stolen session cookies, credentials, and autofill info pulled straight off the infected device," he said. Those artifacts, Lancaster said, are "enough to walk right past [multifactor authentication] by hijacking an already-authenticated session, log into corporate email or VPNs without raising a single alert, and sit there quietly for weeks while they map out the network."
SpyCloud warned directly that "infostealer logs aren’t the end of an incident — they are often the beginning," and noted that access brokers sell these logs to ransomware crews and other fraudsters who want the exact entry points infostealer data provides.
Operational technology, programmable logic controllers, and limits of the analysis
The study reported that 258 of the 1,787 organizations with active infostealer exposure carried credentials to operational technology (OT) or remote-access systems. At the same time, SpyCloud emphasized that its work did not investigate OT devices themselves: "It’s important to note that our research did not focus on OT devices which run the most critical processes within these utilities, and any exposure we cite herein should not be interpreted as exposure of specific OT devices," the report said.
The distinction matters against the backdrop of earlier cyberattacks this summer in Minnesota and elsewhere, which involved internet-exposed programmable logic controllers; SpyCloud’s study did not address that specific vulnerability class.
How the Cybersecurity and Infrastructure Security Agency, water systems, and vendors are implicated
- Cybersecurity and Infrastructure Security Agency (CISA): SpyCloud said it began a responsible-disclosure process and started with a briefing for the Cybersecurity and Infrastructure Security Agency.
- Water and wastewater organizations: The report’s sample suggests that larger operators and organizations linked via vendor relationships are more likely to show identity exposure; the study measures identity exposure rather than confirmed compromise.
- Vendors and supply-chain partners: The smart-meter example highlights how a single infected device at a vendor can expose credentials tied to scores of tenant organizations, producing "cascading supply chain exposure."
U.S. government officials have suspected that a recent wave of cyberattacks hitting the sector are tied to Iran; SpyCloud framed its findings against that evolving operational picture but focused its analysis on identity-exposure data rather than attribution or OT device compromise.
SpyCloud’s own framing leaves a pointed, operational question in plain language. As Lancaster put it: "So, the real question isn’t whether the exposure is dangerous. It’s how much time you have before someone weaponizes that stolen data against you." That timeline — and how rapidly responsible disclosure, CISA briefings, and vendor remediation progress — will determine whether exposed credentials remain a prelude or become the opening move of a wider incident.




