Cybersecurity firm SpyCloud found that over 1,700 U.S. water and wastewater providers are vulnerable to cyberattacks due to stolen employee passwords and active login sessions. The research highlights how easily critical infrastructure can be compromised, with some breaches granting access to operational networks.

The widespread exposure of U.S. water providers to cyberattacks via stolen credentials poses a significant risk to public health and national security, potentially disrupting essential services and compromising critical infrastructure.
New research from cybersecurity firm SpyCloud reveals that over 1,700 U.S. water and wastewater providers are vulnerable to cyberattacks due to stolen employee passwords and active login sessions. The findings highlight the ease with which critical infrastructure can be compromised amidst a wave of hacks targeting water supplies across the United States.
SpyCloud built a database of more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, identifying 10,000 organizations. Their analysis found that password-stealing malware had compromised credentials for 1,787 of these organizations, representing nearly 20% of those checked. Crucially, at least 250 organizations had credentials exposed that appeared to grant access to their operational networks and remote-access systems, which control physical infrastructure like pumps and water flows.
The research noted that a single breach at an unnamed metering tech provider resulted in the theft of credentials for 167 U.S. utility companies that rely on the provider. SpyCloud chief investigations officer Jason Lancaster stated that this single incident provided criminals with access to "a hundred otherwise unrelated organizations."
Password-stealing malware, also known as infostealers, can steal stored passwords and session tokens, allowing hackers to impersonate legitimate users and often bypass multi-factor authentication. These stolen credentials are frequently traded on illicit markets.
While this research focuses on password-based vulnerabilities, it comes weeks after a series of hacks targeting water providers, which the U.S. government has privately linked to Iran-backed actors. SpyCloud found no evidence that those specific Iran-linked attacks utilized stolen passwords, instead pointing to security weaknesses like default passwords on mechanical switches and physical controllers, consistent with earlier findings from CISA. SpyCloud researchers emphasize that stolen passwords remain a significant and accessible entry point for attackers, a risk that coexists with other known security vulnerabilities in critical infrastructure technology.
Pick the topics you care about. Get only what matters, on your cadence.