The findings, published by SpyCloud, underscore the vulnerability of water providers and other critical infrastructure amidst a recent wave of hacks targeting water supplies across dozens of American communities. The company built a database of more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, representing 10,000 organizations. It found that password-stealing malware had swiped credentials from 1,787 organizations — nearly two in 10 providers checked — and that at least 250 organizations had credentials exposed that appeared to allow access to their operational networks and remote-access systems, which control physical pumps and water flows.
SpyCloud’s analysis also covered an unnamed metering technology provider whose network was infected with password-stealing malware. The malware stole credentials for 167 U.S. utility companies that rely on that provider. “This single breach handed criminals the keys to access a hundred otherwise unrelated organizations,” said SpyCloud Chief Investigations Officer Jason Lancaster.
The research comes weeks after a spate of hacks targeting U.S. water providers, which the U.S. government has privately tied to Iran-backed hackers. SpyCloud found no evidence that those Iran-linked hacks relied on stolen passwords. Instead, signs point to security weaknesses such as manufacturer-set default passwords in mechanical switches and physical controllers, echoing earlier findings from U.S. cybersecurity agency CISA. Rather than being a new technique, the research highlights how stolen passwords remain a major source of access for attackers.