A new cybersecurity study has found that stolen passwords are exposing more than 1,700 American water and wastewater providers to potential hacking. Research by SpyCloud, shows that password-stealing malware has compromised credentials belonging to 1,787 organizations—nearly two in every ten providers examined. The findings highlight how basic credential theft, rather than advanced artificial intelligence or sophisticated exploits, can create a serious threat to critical infrastructure.
SpyCloud analyzed a database of more than 66,000 publicly accessible systems registered with the US Environmental Protection Agency, covering roughly 10,000 water-related organizations. The researchers found that malware had stolen passwords and credentials from nearly 20% of these providers. More alarmingly, at least 250 organizations had exposed credentials that appeared to allow access to operational networks and remote-access systems used to control physical pumps and water flows.
The danger is amplified by infostealer malware, which captures not only saved passwords but also active session tokens. These tokens can keep a user logged into a system, allowing attackers to impersonate legitimate employees and sometimes bypass multi-factor authentication. Stolen credentials are frequently traded or sold on underground marketplaces, giving hackers a ready-made way to enter specific organizations without needing to discover new vulnerabilities themselves.
The study also revealed a supply-chain risk. Researchers identified an unnamed metering technology provider whose network contained an infected device. That single compromise exposed credentials for 167 US utility companies that relied on the provider’s technology. This shows how one weak link in a vendor’s security can potentially create access routes into hundreds of unrelated water systems, making third-party cybersecurity oversight essential.
The report comes after a series of cyberattacks on US water providers, which the government has privately linked to Iran-backed hackers. However, SpyCloud said it found no evidence that those particular attacks used stolen passwords; instead, they involved issues such as default passwords on physical controllers and mechanical switches. The broader lesson is clear: water utilities must combine strong password practices, multi-factor authentication, session-security controls, vendor monitoring, and removal of default credentials to protect essential public services.
Read the original article:
