
More than a thousand water utilities across the United States are sitting on a hidden vulnerability that has nothing to do with aging pipes or crumbling treatment plants. According to new research from cybersecurity firm SpyCloud, the danger comes from stolen employee passwords, and it’s exposing a level of password theft water security risk that few outside the industry have fully grasped. The firm’s findings, detailed in a recent report, show that malware built to harvest login credentials has already compromised well over a thousand water and wastewater providers nationwide.
Key takeaways
SpyCloud found that over 1,787 U.S. water and wastewater providers have been exposed to password-stealing malware.
The research covered more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, representing roughly 10,000 organizations.
About 250 providers had credentials exposed that appeared to grant access to operational networks controlling physical pumps and water flows.
A single infected device at an unnamed metering tech provider exposed credentials tied to 167 U.S. utility companies.
Iran-backed hackers who recently targeted U.S. water systems did not rely on stolen passwords, SpyCloud said, pointing instead to hardware weaknesses like default manufacturer passwords.
Widespread Exposure of U.S. Water Providers to Password-Stealing Malware
Nearly one in five water providers checked by SpyCloud turned out to have credentials already stolen by infostealer malware, a scale that suggests this isn’t a fringe problem confined to a handful of poorly defended small utilities. To reach that conclusion, SpyCloud built a database covering more than 66,000 public-facing systems tied to roughly 10,000 organizations registered with the U.S. Environmental Protection Agency. Cross-referencing that database against known malware infections, the firm identified 1,787 organizations whose passwords and credentials had been swiped.
What makes the finding especially concerning isn’t just the raw count of compromised accounts. It’s what some of those stolen credentials could unlock. SpyCloud reported that at least 250 organizations had exposed credentials that appeared capable of reaching operational networks and remote-access systems — the digital controls that govern physical pumps and water flows. That distinction matters: a stolen email password is one thing, but a stolen credential that opens a door to industrial control systems is an entirely different category of risk.
Case Study: Metering Tech Provider’s Network Breach
One incident illustrates just how far a single infection can ripple outward. SpyCloud’s analysis flagged an unnamed metering technology provider whose network contained a device infected with password-stealing malware. From that one infection point, the malware siphoned off credentials tied to 167 U.S. utility companies that relied on the metering provider’s services.
SpyCloud’s Chief Investigations Officer, Jason Lancaster, described the scale of the fallout bluntly, saying the breach handed criminals the keys to access “a hundred otherwise unrelated organizations.” That single sentence captures why this story matters beyond any one utility: a vulnerability in a shared vendor or third-party tech provider can quietly cascade into dozens, even hundreds, of separate victims that never suspected they were exposed.
Password-Stealing Malware Capabilities and Threat Dynamics
Infostealer malware doesn’t just grab a username and password sitting in a browser’s saved-login list. It also captures active session tokens — the digital markers that keep a user logged in without having to re-enter credentials every time. That second piece is what makes this threat particularly dangerous for critical infrastructure operators who assume multi-factor authentication keeps them safe.
How the Malware Bypasses Multi-Factor Authentication
Session tokens can let a hacker log in as though they were the legitimate account holder, sidestepping the extra verification step that multi-factor authentication is supposed to enforce. In practice, this means an organization can have MFA properly configured and still get breached, simply because the attacker never needed to trigger a login challenge in the first place — they walked in with a token that was already trusted.
Once credentials and tokens are stolen, they rarely stay with a single attacker. Hackers routinely trade stolen login data on underground markets specifically to gain entry into targeted organizations, and SpyCloud’s research underscores that stolen passwords represent an accessible pathway “to whoever wants to buy or find it.” That accessibility is part of what separates this threat from more sophisticated, resource-intensive attack methods — it doesn’t require advanced tools or state-level backing to exploit a leaked credential.
Broader Security Risks and Threat Actors Targeting Water Infrastructure
The SpyCloud findings land just weeks after a separate wave of attacks hit water providers across the country, activity the U.S. government has privately linked to Iran-backed hackers. That connection raises an obvious question: are these credential leaks and the Iran-linked intrusions part of the same problem? SpyCloud’s answer is no.
Iran-Linked Attacks Follow a Different Path
SpyCloud said it found no evidence that the Iran-backed intrusions relied on stolen passwords at all. Instead, the signs in those cases pointed toward security weaknesses baked into the hardware itself — specifically, manufacturer-set default passwords left unchanged on mechanical switches and physical controllers used across critical infrastructure. That observation echoes earlier warnings from the U.S. cybersecurity agency CISA about the same class of hardware vulnerability.
Taken together, the two threads reveal a sector facing pressure from two very different directions at once. One is a modern, credential-driven attack surface fueled by infostealer malware and traded login data. The other is a much older, more basic failure: infrastructure still running on default settings a hacker can guess without stealing anything. As Lancaster put it, the water sector “has to hold both stories at once.” That framing suggests defenders can’t treat password theft water security and hardware hardening as separate projects — closing one gap while leaving the other open still leaves the door ajar.
FAQ
How many U.S. water providers are exposed to password-stealing malware?
Over 1,787 U.S. water and wastewater providers have been found to be exposed to password-stealing malware according to SpyCloud.
What is the risk associated with passwords stolen by this malware?
Stolen passwords and session tokens can allow hackers to access operational networks, including systems controlling physical water infrastructure, often bypassing multi-factor authentication.
Are hackers using stolen passwords in recent attacks by Iran-backed groups on U.S. water providers?
No evidence was found that Iran-backed hackers relied on stolen passwords; instead, they exploited hardware security weaknesses like default manufacturer passwords.
What must water sector security focus on to improve protection against cyber threats?
Security must address both the widespread risk of password theft and vulnerabilities in critical infrastructure hardware.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
