About 1,787 U.S. water and wastewater providers now face elevated risk of operational intrusion after password-stealing malware exfiltrated employees' credentials and active session tokens, according to new research.
Cybersecurity firm SpyCloud built a registry of more than 66,000 public-facing systems that appear in U.S. Environmental Protection Agency records, covering roughly 10,000 organizations. Within that set the company identified credential theft linked to 1,787 organizations, or nearly two in ten of the providers it examined.
SpyCloud said at least 250 of those organizations had exposed credentials that appeared to permit access to operational networks and remote-access systems that control physical pumps and water flows. The firm highlighted an infected device at an unnamed metering technology provider that yielded passwords and session tokens for 167 U.S. utility companies. SpyCloud chief investigations officer Jason Lancaster said that single compromise handed criminals the keys to access "a hundred otherwise unrelated organizations."
Password-stealing malware, sometimes called infostealers, harvests stored login credentials and session tokens used to keep users logged in. Those session tokens can let an attacker impersonate a legitimate user and often circumvent multi-factor authentication. Stolen credentials are frequently traded among criminal buyers and sellers, creating readily available routes into specific organisations.
The findings arrive weeks after a series of hacks against U.S. water systems that the U.S. government has privately linked to Iran-backed actors. SpyCloud said it found no evidence those incidents depended on stolen passwords, and instead pointed to weak factory-set credentials in mechanical switches and controllers used across industrial systems, a vulnerability U.S. cybersecurity agencies have also flagged. Lancaster urged the sector to accept both realities at once, saying it "has to hold both stories at once," and noting stolen passwords are a major source of access to "whoever wants to buy or find it."
SpyCloud's analysis underscores how credential theft and insecure industrial devices can run in parallel, creating multiple paths for attackers to reach systems that directly affect water delivery. The report signals that defending U.S. water infrastructure requires addressing employee endpoints and third-party access as well as the embedded defaults on operational equipment.
