Password rubati: come i criminalità online stanno minacciando le nostre riserve idriche ⟡ Stolen passwords are exposing America’s water providers to hackers

Pare che i nostri impianti idrici siano più a rischio di quanto pensiamo. Un’analisi recente di SpyCloud ha rivelato che oltre mille fornitori di acqua e acque reflue negli Stati Uniti sono esposti a manomissioni, non grazie all’intelligenza artificiale, ma a un virus malvagio che sa rubare le password e le sessioni attive dei dipendenti. In pratica, i malintenzionati hanno una via d’accesso quasi troppo semplice: rubare un credenziale! La cosa si fa più seria quando si parla di infrastrutture critiche. La compagnia ha mappato oltre sessanta sei mila sistemi pubblici e, in un caso eclatante, ha scoperto che l’hackeraggio di un unico fornitore di tecnologia per contatori poteva dare accesso a ben sedici sette impianti uti e a un centinaio di organizzazioni apparentemente non collegate. I criminali usano malware specializzati, gli ‘infostealers’, che non solo spulciano le password salvate, ma rubano anche i ‘session tokens’. Questi ‘token’ sono la roba che permette a un hacker di entrare come se fosse l’utente vero, e soprattutto, possono saltare molti sistemi di autenticazione a più fattori. Il settore idrico, tra l’altro, ha subìto un sacco di attacchi di recente, che il governo ha collegato a hacker supportati dall’Iran. Tuttavia, i ricercatori sottolineano che, mentre alcune incursioni recenti puntano a debolezze strutturali (come password predefinite di fabbrica), le credenziali rubate rimangono una minaccia enorme e facilmente monetizzabile. L’azienda fa benissimo a ricordarci che il settore deve affrontare contemporaneamente queste due facce del problema: le falle tecniche e il rischio continuo rappresentato dalle password rubate.

🇬🇧 Summary in English

It turns out that our water treatment plants might be more exposed than we think. A recent deep dive by SpyCloud has revealed that over a thousand water and wastewater providers across the U.S. are vulnerable to hacking—and the main culprit isn’t some futuristic AI exploit, but a relatively basic piece of malicious software designed to steal employee passwords and active session credentials. Basically, the bad guys have found an almost too-easy backdoor: steal a login detail! The stakes are incredibly high when we talk about critical infrastructure. After mapping over 66,000 public-facing systems, the firm found that a breach at a single metering tech provider could potentially hand hackers the keys to access 167 different utility companies and about a hundred unrelated organizations. These ‘infostealers’ are sophisticated malware that don’t just swipe stored passwords; they also grab ‘session tokens.’ These tokens are the VIP pass that allows a hacker to log in just like the legitimate user, often bypassing multi-factor authentication systems. This is a big headache for the water sector, which has faced numerous hacks lately—some linked by the U.S. government to Iran-backed hackers. However, the researchers point out that while some recent attacks point fingers at systemic flaws (like default manufacturer passwords), stolen credentials remain a massive, easily tradable source of access. The takeaway is a stark reminder: the water industry must contend with two major threats simultaneously—both the technical vulnerabilities and the constant, lucrative risk posed by stolen logins.

Leggi l’articolo originale su TechCrunch →

Fonte: TechCrunch | Argomento: Cybersecurity

#tecnologia #innovazione #technews

{“@context”: “https://schema.org”, “@type”: “NewsArticle”, “headline”: “Password rubati: come i criminalità online stanno minacciando le nostre riserve idriche ⟡ Stolen passwords are exposing America’s water providers to hackers”, “description”: “Pare che i nostri impianti idrici siano più a rischio di quanto pensiamo. Un’analisi recente di SpyCloud ha rivelato che oltre mille fornitori di acqua e acque reflue negli Stati Uniti sono esposti a manomissioni, non grazie all’intelligenza artifici…”, “image”: “https://techcrunch.com/wp-content/uploads/2026/09/glen-canyon-dam-2290782874-getty.jpg?resize=1200,818”, “datePublished”: “2026-09-22T19:32:32.943916”, “author”: {“@type”: “Person”, “name”: “Alessandro Mauro Guerra”, “url”: “https://www.alessandroguerra.net/autore/”}, “publisher”: {“@type”: “Organization”, “name”: “TechMAG”, “logo”: {“@type”: “ImageObject”, “url”: “https://www.alessandroguerra.net/wp-content/uploads/2026/logo.png”}}, “mainEntityOfPage”: “https://techcrunch.com/2026/09/22/stolen-passwords-are-exposing-americas-water-providers-to-hackers/”, “keywords”: “tecnologia, innovazione, tech news”}

Potrebbe interessarti