
More than a thousand U.S. water and wastewater providers appear exposed to hackers because of malware that steals employees’ passwords and logged-in session data, according to new research from cybersecurity firm SpyCloud. The findings add another layer of risk for critical infrastructure already facing a wave of attacks, and they show how ordinary stolen credentials can still be one of the easiest ways into a network.
SpyCloud’s look at the water sector
SpyCloud said it built a database of more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, representing about 10,000 organizations. From that pool, the company found password-stealing malware had collected credentials from 1,787 organizations, or nearly two in 10 of the providers it examined.
The company said at least 250 organizations had exposed credentials that appeared to provide access to operational networks and remote-access systems. Those are the environments that can control physical pumps and water flows, making them especially sensitive in a sector where cyber incidents can quickly become public safety issues.
Why stolen passwords remain so effective
Password-stealing malware, often called infostealers, is designed to capture saved passwords and session tokens from infected devices. Those session tokens can let an attacker impersonate a user without needing to know the password itself, and in some cases they can bypass multi-factor authentication.
That makes stolen credentials a durable and low-cost entry point for criminals. SpyCloud’s point is not that attackers need advanced artificial intelligence tools to break in, but that they can often buy or trade access that has already been stolen from employees, contractors or technology vendors.
- Infostealers can grab passwords stored in browsers or apps.
- They can also capture active session tokens.
- Stolen tokens may let attackers log in as the real user.
- Some of these logins can bypass multi-factor protections.
A vendor breach with broad fallout
The research also examined an unnamed metering technology provider. SpyCloud said one device on that provider’s network was infected with password-stealing malware, which in turn stole a large set of credentials, including passwords for 167 U.S. utility companies that rely on the metering tech provider.
SpyCloud Chief Investigations Officer Jason Lancaster said in the post that the single breach gave criminals the keys to access “a hundred otherwise unrelated organizations.” The example illustrates how one compromised vendor can create a wide blast radius across utilities that depend on the same technology partner.
How this fits into the broader water security picture
The research comes just weeks after a series of hacks targeting water providers across the United States. The U.S. government has privately tied those incidents to Iran-backed hackers, though SpyCloud said it found no evidence that those attacks relied on stolen passwords.
Instead, SpyCloud said those incidents appear to have exploited other weaknesses, including manufacturer-set default passwords in the switches and physical controllers used by critical infrastructure. That assessment echoes earlier warnings from the U.S. Cybersecurity and Infrastructure Security Agency, which has repeatedly urged operators to secure exposed devices and change default credentials.
The distinction matters. The new research suggests that water utilities face at least two parallel threats: targeted attacks that exploit insecure hardware and simpler credential theft that can open doors to internal systems, remote access tools and operational technology environments.
What the findings say about critical infrastructure risk
Water providers are often smaller organizations with limited security staff, but they operate systems that can have outsized consequences if disrupted. SpyCloud’s report suggests that credential theft continues to be a major weakness across the sector, even when attackers do not need to defeat more advanced defenses.
It also shows how interconnected the ecosystem has become. A single infected vendor device can expose dozens or even hundreds of utilities, while stolen credentials can circulate long after the original compromise. For operators, that means security is no longer limited to their own staff devices and local networks; it extends to contractors, technology providers and any system that can touch a login.
Key takeaways from the research
- SpyCloud identified 1,787 organizations with stolen credentials among the systems it checked.
- At least 250 organizations had credentials that could expose operational or remote-access networks.
- A compromised metering tech provider exposed passwords for 167 U.S. utility companies.
- Infostealers can steal both passwords and session tokens, sometimes sidestepping multi-factor authentication.
- SpyCloud said the recent Iran-linked hacks did not appear to rely on stolen passwords.
The water sector, “both stories at once”
In SpyCloud’s view, utilities need to think about the recent hack wave and the credential-theft problem at the same time. Lancaster said the water sector “has to hold both stories at once,” meaning operators cannot focus only on one class of threat and assume the rest will fade away.
That framing is important because stolen passwords remain attractive to attackers precisely because they are simple, scalable and widely available. For a critical infrastructure sector that is already under pressure, the report suggests that basic credential hygiene may be just as important as defending against more visible nation-state tactics.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 22, 2026 at 10:33 pm
0 views
