SpyCloud finds stolen passwords exposing water providers

SpyCloud says credentials from 1,787 U.S. water organizations were exposed, with some appearing to open paths into operational and remote-access systems.
New security research suggests that more than a thousand U.S. water and wastewater providers may be exposed to hackers because malware stole employees’ passwords and active login sessions.
The findings from cybersecurity firm SpyCloud add a fresh angle to the recent run of attacks on water systems in the United States. The worry is not just that critical infrastructure can be targeted, but that attackers may get in through stolen credentials — often without needing sophisticated tools. As IT-PUB News notes, that shifts attention from direct attacks on equipment to the quieter risk of compromised logins.
SpyCloud found exposed credentials across thousands of systems
SpyCloud said it built a database of more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, covering about 10,000 organizations.
From that pool, the company found that password-stealing malware had taken passwords and credentials from 1,787 organizations, or nearly two in 10 providers it checked. SpyCloud also said at least 250 organizations had exposed credentials that appeared to provide access to operational networks and remote-access systems.
Those systems matter because they can control physical pumps and water flows. So this is more than a routine account-security issue. In some cases, stolen credentials could give outsiders a path into the tools that keep water infrastructure running.
Stolen sessions can bypass normal login protections
The malware involved is commonly known as an infostealer. It can grab stored passwords, but also session tokens — the data that keeps users logged in.
That makes the problem more serious. Session tokens can sometimes let an attacker act as if they were the legitimate user, and they can often bypass multi-factor authentication. Even a security layer that blocks password-only logins may not help if a valid session has already been stolen.
SpyCloud also said hackers routinely trade stolen credentials to gain access to specific organizations. Its research suggests password theft remains a practical route into networks, even without AI-powered attacks.
One infected vendor device exposed many utility accounts
The analysis also examined an unnamed metering technology provider. SpyCloud said a device on that provider’s network was infected with password-stealing malware, which then captured a large number of credentials.
Among the stolen data were passwords for 167 U.S. utility companies that rely on the metering tech provider. Jason Lancaster, SpyCloud’s chief investigations officer, said in the post that the breach effectively gave criminals the keys to access “a hundred otherwise unrelated organizations.”
It is a sharp example of how a single compromise can spread well beyond one company. When a vendor or service provider is hit, the fallout can reach many separate utilities that depend on it.
SpyCloud separates this risk from recent Iran-linked hacks
The research comes weeks after a series of hacks targeting water providers across the U.S. that the government has privately linked to Iran-backed hackers.
SpyCloud said it found no evidence that those incidents involved stolen passwords. In those cases, the signs instead pointed to basic security weaknesses in equipment used by critical infrastructure, including manufacturer-set default passwords on mechanical switches and physical controllers.
The company said that matches earlier findings from the U.S. cybersecurity agency CISA.
The distinction matters. It points to two different ways water systems can be exposed: weak or default settings on devices, and stolen credentials that can be bought, found, or harvested by malware.
Water providers and vendors face two security problems at once
SpyCloud’s message is that the water sector has to deal with both issues at the same time. Stolen passwords remain a major source of access for “whoever wants to buy or find it,” Lancaster said, while infrastructure equipment itself still carries known security risks.
For water providers, the findings raise difficult questions about how much access is still protected by passwords alone, and how much may already be circulating in criminal markets. For the broader digital environment, the report is another reminder that attacks on critical services often begin with something as ordinary as a stolen login.
The research does not say all of the exposed organizations were breached in the same way, or that every exposed credential was actively used. But it does show how password-stealing malware can create a wide blast radius, especially when it reaches vendors or systems connected to multiple utilities.
For communities that depend on these providers, the risk is not abstract. Water systems are part of the infrastructure people rely on every day, and the security of digital access can carry physical consequences.