Stolen passwords are exposing America’s water providers to hackers

Research by SpyCloud reveals that malware has stolen passwords and session tokens from 1,787 U.S. water and wastewater providers, exposing operational networks for nearly one in ten surveyed entities. The report highlights credential theft as a simple path to critical infrastructure compromise, underscoring urgent need for stronger access controls.

Cover image for Stolen passwords are exposing America’s water providers to hackers

Research by SpyCloud shows that malware capable of stealing passwords and active session tokens has compromised the accounts of 1,787 U.S. water and wastewater providers. The stolen credentials include both static passwords and session tokens that can bypass multi‑factor authentication, giving attackers direct entry to operational networks. SpyCloud describes the malware as an “infostealer,” a tool that harvests stored credentials and then trades them on underground markets. The breach covers roughly two in ten of the 10,000 organizations listed in a database of more than 66,000 public‑facing systems registered with the EPA. At least 250 of those entities appear to have had credentials that grant access to remote‑access systems controlling pumps and water flows. A single compromised metering‑technology provider leaked passwords for 167 utility companies, effectively handing criminals the keys to “a hundred otherwise unrelated organizations,” according to SpyCloud’s chief investigations officer. The report urges water utilities to adopt stronger access controls, including the replacement of default passwords and the enforcement of robust multi‑factor authentication. Organizations should also monitor for signs of credential reuse and regularly rotate passwords to reduce the risk of infostealer exploitation. Enhanced network segmentation and continuous monitoring of privileged accounts are recommended to limit the impact of any stolen credentials.