Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-23 · updated: 2026-09-23 · tags: [incident, energy-utilities, supply-chain] · confidence: high · severity: high · affected_sectors: [energy-utilities] · au_impact: true

SpyCloud built a database of 66,845 EPA-registered water systems, analysed 10,000 organisations and found 1,787 — close to two in ten — with identity data actively exposed through infostealer-harvested credentials, 258 of which carried logins for operational technology or remote-access systems. The most consequential finding is a supply-chain cascade rather than a utility: a single infected device at an unnamed smart-meter technology provider held saved logins tied to roughly 167 different US utility metering tenants, so one compromised laptop opened a door to many operators. SpyCloud is careful about what the measurement is — "it measures identity exposure, not confirmed intrusion" — and notes the study did not examine OT devices, though its own conclusion is that exposure concentrates in larger operators and in the vendor supply chain rather than in small utilities. The report follows months of attacks on the sector that US officials suspect are tied to Iran, and SpyCloud has begun a responsible-disclosure process, starting with a briefing for CISA. The practical use is as a proactive check: for utilities, whether their own vendor or contractor credentials appear in stealer logs is now an answerable question.

Attribute Detail
Sector Energy & Utilities
Date 2026-09-23
Source SpyCloud
Reliability Tier 2