Stolen Passwords Expose U.S. Water Providers to Cyberattacks

Cybersecurity research has found thousands of U.S. water providers exposed by stolen passwords and session data from malware attacks.

Sep 22, 2026 - 15:35
 2
Stolen Passwords Expose U.S. Water Providers to Cyberattacks
Image Credit: TechAmerica.ai / AI-generated image

New cybersecurity research found that more than a thousand U.S. water and wastewater providers may be exposed to cyberattacks because malware steals employee passwords and active login sessions.

Findings from cybersecurity company SpyCloud highlight how password-stealing malware, also known as infostealers, can give attackers a direct path into critical infrastructure networks.

Stolen Credentials Create Infrastructure Risks

SpyCloud analysed more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, representing about 10,000 organisations. The company found that malware had collected passwords and credentials from 1,787 organisations.

At least 250 organisations had exposed credentials that appeared capable of providing access to operational networks and remote-access systems used to manage physical equipment, including pumps and water flow controls.

The research also examined an unnamed metering technology provider whose network had been infected with password-stealing malware. The malware collected credentials connected to 167 U.S. utility companies that relied on the provider’s technology.

How Infostealer Malware Works

Infostealers can collect stored passwords and session tokens, which let users stay logged into online services. Attackers can use stolen session tokens to access accounts while potentially bypassing some multi-factor authentication protections.

Cybercriminals often trade or sell stolen credentials, creating opportunities to access organisations without needing advanced hacking techniques.

Separate From Recent Water Sector Attacks

The research comes after several cyber incidents targeting water providers in the United States. U.S. officials have linked some recent attacks to Iran-backed hackers, but SpyCloud said it found no evidence that those incidents relied on stolen passwords.

Instead, those attacks appeared connected to other security weaknesses, including default passwords on industrial devices and controllers, issues previously highlighted by the U.S. Cybersecurity and Infrastructure Security Agency.

SpyCloud said water organisations must address both known technology vulnerabilities and the risks created by exposed employee credentials as cyber threats against critical infrastructure continue.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav’s current bio says she reports on technology-focused developments “in India”, but the same profile publishes stories about U.S. NHTSA investigations, Hugging Face, global AI startups and other international topics.