Stolen passwords are exposing America’s water providers to hackers
Cybersecurity firm SpyCloud found that password-stealing malware has exposed credentials from hundreds of U.S. water and wastewater providers, potentially giving attackers direct access to operational networks. The research examined EPA-registered public-facing systems and identified stolen passwords and session tokens from organizations that operate critical water infrastructure.

Why It Matters
The findings show an additional, widespread attack vector that can be used to compromise critical infrastructure: stolen credentials and session tokens that can bypass protections and grant access to systems controlling physical water operations. This amplifies other recent incidents that exploited device and configuration weaknesses in water-supply systems.
Key Facts
- Researcher: SpyCloud (cybersecurity defense firm)
- Dataset size: over 66,000 public-facing systems registered with the U.S. EPA
- Organizations covered: about 10,000 organizations
- Organizations with stolen credentials: 1,787 organizations
- Proportion affected: nearly two in 10 providers checked by SpyCloud were compromised by password-stealing malware.
New analysis from cybersecurity firm SpyCloud found that password-stealing malware has captured credentials from a substantial number of U.S. water and wastewater providers, creating pathways for attackers to access operational systems. SpyCloud assembled a database of more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, representing roughly 10,000 organizations, and identified stolen passwords or session tokens tied to 1,787 of those organizations.
The firm reported that at least 250 of the affected organizations had exposed credentials that appeared to permit access to operational networks and remote-access systems responsible for controlling pumps and water flows. SpyCloud highlighted an incident involving an unnamed metering technology provider whose infected device yielded credentials for 167 U.S. utility companies, a single breach that the company said effectively gave criminals entry points into dozens of otherwise unrelated organizations.
Password-stealing malware, often called infostealers, harvests stored passwords and active session tokens. Those session tokens can let an attacker impersonate a logged-in user and may sometimes bypass multi-factor authentication. SpyCloud noted that stolen credentials are regularly traded, offering a ready supply of login data for people seeking entry to specific organizations.
SpyCloud’s findings come after a recent wave of hacks against U.S. water providers that U.S. officials have privately attributed to Iran-linked actors. The company said it found no evidence the Iran-linked intrusions relied on stolen passwords; instead, those incidents pointed to other security weaknesses such as manufacturer-set default passwords and exposed industrial controllers. SpyCloud’s reporting emphasizes that the water sector faces both device- and credential-related risks simultaneously, according to Chief Investigations Officer Jason Lancaster.
Keep Reading

TikTok’s US arm joins Lantern, a cross-platform child safety initiative

Exhibit tables added: One last chance to showcase your startup at TechCrunch Disrupt 2026
