Stolen passwords expose over a thousand US water providers to hackers, research finds

SpyCloud analysis finds nearly 2 in 10 water utilities have had employee credentials stolen by infostealer malware

By LineZotpaper
Published
Read Time2 min
New research from cybersecurity defense firm SpyCloud has found that well over a thousand U.S. water and wastewater providers are vulnerable to hacking due to malware that has stolen employees' passwords and active login sessions, highlighting a relatively simple avenue for attackers to access critical infrastructure.

The findings, published by SpyCloud, underscore the vulnerability of water providers and other critical infrastructure amidst a recent wave of hacks targeting water supplies across dozens of American communities. The company built a database of more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, representing 10,000 organizations. It found that password-stealing malware had swiped credentials from 1,787 organizations — nearly two in 10 providers checked — and that at least 250 organizations had credentials exposed that appeared to allow access to their operational networks and remote-access systems, which control physical pumps and water flows.

SpyCloud’s analysis also covered an unnamed metering technology provider whose network was infected with password-stealing malware. The malware stole credentials for 167 U.S. utility companies that rely on that provider. “This single breach handed criminals the keys to access a hundred otherwise unrelated organizations,” said SpyCloud Chief Investigations Officer Jason Lancaster.

The research comes weeks after a spate of hacks targeting U.S. water providers, which the U.S. government has privately tied to Iran-backed hackers. SpyCloud found no evidence that those Iran-linked hacks relied on stolen passwords. Instead, signs point to security weaknesses such as manufacturer-set default passwords in mechanical switches and physical controllers, echoing earlier findings from U.S. cybersecurity agency CISA. Rather than being a new technique, the research highlights how stolen passwords remain a major source of access for attackers.

§

Analysis

Why This Matters

  • The exposure of water utility credentials means attackers could disrupt or manipulate water treatment and distribution systems, affecting public health and safety.
  • Password-stealing malware offers a low-tech entry point that bypasses more advanced defenses, making critical infrastructure vulnerable even to less sophisticated adversaries.
  • The breach of a single third-party provider (the metering tech company) illustrates supply-chain risks: one infection can cascade across hundreds of utilities.

Background

Water and wastewater systems in the U.S. are part of the nation's critical infrastructure, overseen by the Environmental Protection Agency and defended by cybersecurity agencies like CISA. In recent months, a series of attacks have targeted water utilities across the country, with the U.S. government attributing some to Iranian-backed hackers. Those intrusions have largely exploited default or weak passwords on industrial control equipment, but the new SpyCloud research shines a light on an equally persistent threat: employee credentials stolen through infostealer malware, which can be traded and reused to gain network access.

Key Perspectives

Water utility operators: Must now contend with the reality that their employees' personal devices or work computers may have been compromised, granting attackers access to internal systems. Many small and medium-sized water providers lack dedicated cybersecurity staff. SpyCloud (security researchers): Argue that stolen passwords and session tokens are a widespread, underappreciated vulnerability. Their database shows that exposed credentials are not theoretical — they are already in the hands of criminals and can be used immediately. U.S. government (CISA) and water sector regulators: While focused on the Iran-linked hacks exploiting default passwords, they must also address the infostealer threat. The differing attack vectors — default passwords vs. credential theft — require separate mitigation strategies.

What to Watch

  • Whether CISA or the EPA issues new guidance or mandates for water utilities regarding password hygiene, multi-factor authentication, and session token protection.
  • The adoption of credential monitoring services by critical infrastructure sectors, following SpyCloud’s findings.
  • Any escalation of attacks using the stolen credentials identified in the research, particularly against the 250 organizations with exposed operational network access.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.