SpyCloud finds infostealer malware exposed passwords at 1,787 U.S. water utilities
Cybersecurity firm SpyCloud analyzed over 66,000 public-facing systems tied to roughly 10,000 EPA-registered water and wastewater organizations and discovered that infostealer malware had already harvested login credentials from 1,787 of them. At least 250 of those organizations had exposed credentials that could grant access to operational networks controlling physical pumps and water flow. In one case, malware on a device belonging to a metering technology vendor exposed passwords for 167 utilities that relied on its services.
GoKawiil's interpretation of the reporting above, not reported fact.
Stolen passwords and session tokens let attackers bypass multi-factor authentication entirely, giving criminals a low-effort way into critical infrastructure without needing sophisticated hacking tools. Because a single compromised vendor can expose credentials across dozens of unrelated utilities, the water sector's reliance on shared third-party tech creates a single point of failure that could ripple across many communities at once.
- SpyCloud found infostealer malware had compromised credentials at 1,787 of roughly 10,000 U.S. water and wastewater organizations examined.
- At least 250 organizations had exposed credentials capable of reaching operational systems controlling physical water infrastructure.
- A single infected device at a metering tech vendor exposed passwords for 167 separate utility customers, showing how third-party breaches cascade.
YubiKey 5 NFC Security Key — Password-stealing malware is putting critical infrastructure like water providers at risk, and hardware security keys are one of the strongest defenses against credential theft. A YubiKey adds phishing-resistant multi-factor authentication so stolen passwords alone can't grant attackers access to sensitive systems.
See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: techcrunch.com — Zack Whittaker, 2026-09-22
Published there as: “Stolen passwords are exposing America’s water providers to hackers”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.