Stolen Passwords Expose 1,787 Water Providers
SpyCloud research finds infostealer malware has harvested credentials tied to 1,787 U.S. water and wastewater organizations, some reaching operational networks.
Roughly two in every ten U.S. water and wastewater organizations checked by a security vendor have had passwords and active login sessions stolen by malware running silently on employee machines. Those credentials don't just open an email inbox — in at least 250 cases they appeared to open the operational networks and remote-access systems that control physical pumps and water flows.
The finding, published by the cybersecurity defense firm SpyCloud, offers a second, more mundane explanation for how America's water systems keep getting hit, running alongside the better-publicized attacks that the U.S. government has privately tied to Iran-backed hackers. SpyCloud says it found no evidence the Iran-linked intrusions relied on stolen passwords at all.
66,000 Systems, 10,000 Organizations
To arrive at those numbers, SpyCloud said it assembled a database of more than 66,000 public-facing systems that are registered with the U.S. Environmental Protection Agency, a set that maps to 10,000 organizations. The company then checked whether credentials for those organizations were already circulating among the stolen-password data it tracks.
They were. SpyCloud found that password-stealing malware had swiped passwords and credentials from 1,787 organizations — nearly two in ten of the providers it examined. The researchers said at least 250 organizations had credentials exposed that appeared to allow access to operational networks and remote-access systems, the equipment that governs pumps and water flows.
That distinction matters. An exposed email password is an annoyance. An exposed password for a remote-access gateway that reaches a physical controller is a different category of problem, and it is the category SpyCloud says it observed at scale.
The Metering Provider That Opened Many Doors
The research also traced a single infection outward. SpyCloud said its analysis covered an unnamed metering technology provider that had a device on its network infected with password-stealing malware.
The malware stole reams of credentials from that machine, including passwords for 167 U.S. utility companies that rely on the metering technology provider. One compromised endpoint at an intermediary turned into access material for a long list of downstream customers.
SpyCloud chief investigations officer Jason Lancaster wrote in the post that this single breach handed criminals the keys to access "a hundred otherwise unrelated organizations."
"a hundred otherwise unrelated organizations"
— Jason Lancaster, chief investigations officer at SpyCloud
Lancaster's framing points at the supply-chain shape of the problem: water utilities frequently do not run every piece of their technology stack themselves, and the smaller vendors that do sit in the middle of the relationship become a shared point of failure.
How Infostealers Bypass the Login Wall
The malware at the center of this is known as an infostealer. These programs are built to harvest a person's saved passwords, but they also capture the session tokens that keep a user logged in to a service.
That second capability is what makes the class of malware so effective. A session token lets an attacker log in as though they were the legitimate user, and it can often bypass multi-factor authentication systems entirely — no code prompt, no push notification, no second factor to defeat, because the session is already authenticated.
Stolen credentials of both kinds are regularly traded so that buyers can obtain passwords or session tokens for specific organizations. The transaction is not sophisticated. The malware does the collection, the market does the matching, and the buyer walks in through a door that was left unlocked.
SpyCloud's report notes that none of this requires AI tooling. The researchers describe stolen passwords as an easy route into an organization's network without using AI tools — an old, cheap, well-understood method that keeps working.
Two Problems, Not One
The SpyCloud findings land weeks after a wave of hacks against water providers around the United States, which the U.S. government has privately tied to Iran-backed hackers.
SpyCloud said it found no evidence that those Iran-linked hacks relied on stolen passwords. In those cases, the researchers said, the signs point to security weaknesses such as manufacturer-set default passwords in the mechanical switches and physical controllers used by critical infrastructure.
That diagnosis echoes earlier findings from the U.S. cybersecurity agency CISA. The picture that emerges is not one campaign but two distinct exposure paths running in parallel: weak default credentials baked into industrial hardware, and stolen credentials swept up from ordinary employee devices.
Lancaster said the water sector "has to hold both stories at once."
Why Utilities Are a Soft Target
Water and wastewater providers are numerous, geographically dispersed, and often small. SpyCloud's EPA-derived dataset of 10,000 organizations describes an attack surface made up mostly of modest operations rather than a handful of hardened enterprises.
That structure shapes what an attacker can do with a single stolen password. Remote-access systems at these organizations frequently exist so that staff and contractors can reach equipment without being physically present. When a credential for one of those systems leaks, the distance between a keyboard and a pump narrows considerably.
SpyCloud's research suggests the exposure is not concentrated in a few large, well-resourced utilities but spread across the sector — 1,787 organizations out of roughly 10,000, with at least 250 showing credentials that appeared to reach operational and remote-access systems.
What the Numbers Actually Show
The scale of the dataset behind the findings is worth separating from the scale of the confirmed exposure, because the two figures answer different questions. SpyCloud measured a population, then measured how much of it had already leaked.
- 66,000+ — public-facing systems registered with the EPA that SpyCloud compiled into its database
- 10,000 — organizations those systems map to
- 1,787 — organizations where password-stealing malware had swiped passwords and credentials, nearly two in ten of those checked
- 250 — organizations, at minimum, with credentials exposed that appeared to allow access to operational networks and remote-access systems
- 167 — U.S. utility companies whose passwords were stolen from a single unnamed metering technology provider
Each figure is a measurement of what was already in the wild when SpyCloud looked, not a prediction. The 250-organization figure is stated as a floor, meaning the true count of exposed operational credentials could be higher.
The Intermediary Problem
The metering provider case illustrates a pattern that extends beyond water: the organizations holding the most sensitive access are not always the ones with the security budget, and the vendors serving them often hold credentials that reach many customers at once.
One infected device at that provider yielded passwords for 167 utilities. That is a consolidation of risk — the kind that makes a single unpatched laptop or a single careless download matter far beyond the organization that owns it.
SpyCloud's report frames the stolen-password route as a major source of access for "whoever wants to buy or find it," in parallel to the known security risks with critical infrastructure technology. The phrase captures an uncomfortable reality about credential markets: the material is available, and access does not require a nation-state or a novel exploit.
Notably, the research arrives with no indication that the two problems — default passwords in industrial hardware and infostealer-harvested credentials — are connected. SpyCloud says the Iran-linked activity shows no signs of relying on stolen passwords, and the stolen-password exposure shows no signs of requiring the industrial hardware weaknesses. They are separate doors into the same buildings.
What Water Providers Can Control
The portion of this problem that utilities can directly influence is the credential side. SpyCloud's findings describe credentials stolen from devices — meaning the exposure begins with malware on an endpoint, not with a flaw in the water system itself.
That places weight on the usual endpoint protections, but also on a factor specific to this malware class: session tokens. Because stolen session tokens can bypass multi-factor authentication, organizations that treat MFA as a complete answer to credential theft may still be exposed after an infostealer runs on a machine. Session invalidation and monitoring for anomalous session use sit in a different defensive layer than MFA prompts.
The research also points to the value of knowing what is already leaked. SpyCloud built its picture by checking a defined population against credential data it already tracked, which is the same exercise an individual organization can run to learn whether its own accounts appear in stolen-credential datasets.
The Stakes Beyond the Pump House
For the utilities named in aggregate but not individually in this research, the practical implication is that their exposure may not originate inside their own walls. A password stolen from a metering vendor's laptop can reach an operational network at a utility that never had malware on any of its machines.
For the vendors serving water providers, the finding suggests that their own endpoint hygiene functions as shared infrastructure for their customers — one compromised device translated into credentials for 167 utilities in the case SpyCloud examined.
For everyone downstream of a water system, the two-track picture is the part worth holding onto. The dramatic version of this story involves foreign hackers and industrial controllers with default passwords. The quieter version involves commodity malware, a reused password, and a session token that never expires when it should. SpyCloud's numbers suggest the quiet version is not rare: nearly two in ten providers checked had credentials already loose, and at least 250 had material that appeared to reach the systems moving water. As long as both paths remain open, this suggests the sector's exposure will be governed by whichever one an attacker finds first.
Sources
- TechCrunch Original source
- cybersecurity defense firm SpyCloud Also reporting
- wave of hacks Also reporting
- infostealers Also reporting
- earlier findings Also reporting
Continue Reading
Fake Job Interviews Fuel North Korea Crypto Theft
A joint advisory links WaterPlum's developer-targeting campaign to over $10.7m in stolen cryptocurrency and 30,000 infected devices worldwide.
EvilTokens Takedown Nets Two Arrests in UK
Microsoft-led coalition seizes 50 phishing sites and disables 150 domains tied to an AI-enabled service that compromised 12,000 inboxes.
Defender zero-day halts antivirus updates
A researcher's new Windows Defender zero-day prevents signature and platform updates, the latest in a string of exploits tied to a dispute with Microsoft.