Password-stealing malware puts thousands of U.S. water utilities at risk
Research by SpyCloud shows that malware has harvested credentials from over 1,700 U.S. water and wastewater providers, exposing many to potential intrusion.
A cybersecurity firm has identified widespread credential theft affecting U.S. water and wastewater providers. By building a database of over 66,000 systems registered with the Environmental Protection Agency, the firm examined roughly 10,000 organizations and found that password-stealing malware compromised the accounts of 1,787 entities. At least 250 of those exposed credentials appear to allow entry into operational networks and remote-access controls that manage physical water infrastructure.
The investigation highlighted a breach at an unnamed metering technology supplier, where the malware harvested credentials for 167 utility companies, effectively giving attackers keys to many unrelated providers. Such infostealers capture both passwords and active session tokens, which can often sidestep multi-factor authentication measures. While recent water-sector hacks have been linked to state-backed actors exploiting default passwords, this research underscores that stolen credentials remain a major vulnerability for critical infrastructure.
Why it matters
Compromised passwords could let hackers disrupt water services that millions rely on daily.
In this story
