Techcrunch iconTechcrunchSep 22, 2026 ~3 min source read

Stolen passwords are exposing America’s water providers to hackers

New research from SpyCloud finds password‑stealing malware has captured credentials tied to thousands of U.S. water and wastewater systems, including access that could reach operational control networks.

Stolen passwords are exposing America’s water providers to hackers

Share this story

Send the public story page.

Useful takeaways from this story.

At least 250 organizations had exposed credentials that appeared to grant access to operational or remote‑access systems that control pumps and flows.

Password‑stealing malware (infostealers) can harvest saved passwords and session tokens that may bypass multi‑factor authentication.

A single breached metering technology provider yielded credentials for 167 U.S. utilities, showing how one compromise can affect many organizations.

# What the research says

SpyCloud also identified at least 250 organizations with credentials exposed that appeared to allow access to operational networks and remote‑access systems that control physical infrastructure, such as pumps and water flows.

# How the malware works

These stolen credentials are traded in criminal markets so attackers can find logins for specific organizations.

# One breach, many victims SpyCloud detailed a case involving an unnamed metering technology provider. A device on that provider's network was infected with password‑stealing malware. The malware harvested large numbers of credentials, including passwords tied to 167 U.S. utility companies that relied on that metering provider. The firm said that single breach effectively gave criminals access to "a hundred otherwise unrelated organizations."

# Relation to recent water sector hacks The research arrives after a wave of hacks against water providers across the U.S. The government has privately linked some of those incidents to Iran‑backed hackers, but SpyCloud said it found no evidence that those particular attacks relied on stolen passwords.

Instead, SpyCloud pointed to other security weaknesses in those incidents, such as devices left with manufacturer‑set default passwords in mechanical switches and physical controllers. The company said the sector faces both problems: compromised or weak controller devices and traded stolen credentials.

# Why this matters for water systems Stolen credentials that reach operational systems create a direct path to control infrastructure. The combination of infostealers capturing session tokens and weak defaults in industrial controllers increases the number of distinct ways an attacker can gain access.

# Concrete examples and scale

  • SpyCloud examined about 66,000 public‑facing EPA‑registered systems (roughly 10,000 organizations).
  • At least 250 organizations had credentials that appeared to permit access to operational or remote‑access systems.
  • A single infected device at a metering vendor exposed credentials for 167 utilities.

# Bottom line The research shows credential theft remains an active and effective attack vector against U.S. water and wastewater providers. Stolen passwords and session tokens are traded and can grant direct access to operational systems, while separate incidents have exploited weak defaults and insecure device configurations. The water sector faces both types of risk at once, which increases the avenues available to attackers.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app