# What the research says
SpyCloud also identified at least 250 organizations with credentials exposed that appeared to allow access to operational networks and remote‑access systems that control physical infrastructure, such as pumps and water flows.
# How the malware works
These stolen credentials are traded in criminal markets so attackers can find logins for specific organizations.
# One breach, many victims SpyCloud detailed a case involving an unnamed metering technology provider. A device on that provider's network was infected with password‑stealing malware. The malware harvested large numbers of credentials, including passwords tied to 167 U.S. utility companies that relied on that metering provider. The firm said that single breach effectively gave criminals access to "a hundred otherwise unrelated organizations."
# Relation to recent water sector hacks The research arrives after a wave of hacks against water providers across the U.S. The government has privately linked some of those incidents to Iran‑backed hackers, but SpyCloud said it found no evidence that those particular attacks relied on stolen passwords.
Instead, SpyCloud pointed to other security weaknesses in those incidents, such as devices left with manufacturer‑set default passwords in mechanical switches and physical controllers. The company said the sector faces both problems: compromised or weak controller devices and traded stolen credentials.
# Why this matters for water systems Stolen credentials that reach operational systems create a direct path to control infrastructure. The combination of infostealers capturing session tokens and weak defaults in industrial controllers increases the number of distinct ways an attacker can gain access.
# Concrete examples and scale
- SpyCloud examined about 66,000 public‑facing EPA‑registered systems (roughly 10,000 organizations).
- At least 250 organizations had credentials that appeared to permit access to operational or remote‑access systems.
- A single infected device at a metering vendor exposed credentials for 167 utilities.
# Bottom line The research shows credential theft remains an active and effective attack vector against U.S. water and wastewater providers. Stolen passwords and session tokens are traded and can grant direct access to operational systems, while separate incidents have exploited weak defaults and insecure device configurations. The water sector faces both types of risk at once, which increases the avenues available to attackers.