· via TechCrunch
Stolen employee credentials expose nearly 1,800 US water providers to hackers
SpyCloud research found password-stealing malware has siphoned credentials from 1,787 US water providers, some of which grant access to systems that control physical pumps and water flow.

Nearly one in five providers affected
New research from cybersecurity firm SpyCloud, reported by TechCrunch, has found that well over a thousand US water and wastewater providers are exposed to intrusion because password-stealing malware has harvested their employees' login credentials and active sessions.
SpyCloud assembled a database of more than 66,000 public-facing systems registered with the US Environmental Protection Agency, corresponding to about 10,000 organizations. Matching that inventory against data siphoned by infostealer malware, the firm found credentials stolen from 1,787 providers, nearly two in ten of those examined. At least 250 organizations had credentials exposed that appeared to grant access to operational networks and remote-access systems, the layer that governs physical pumps and water flows.
How infostealers turn logins into breaches
Infostealers are a long-established class of malware that grabs a victim's stored passwords along with the session tokens that keep them logged in to websites and services. A stolen session token can let an attacker resume a session as the legitimate user, which frequently sidesteps multi-factor authentication. According to TechCrunch, criminals routinely trade these stolen credentials to obtain access to specific organizations, and SpyCloud's findings underline that password theft alone, without any AI-assisted tooling, is enough to put water utilities at risk.
One vendor infection reached 167 utilities
The analysis included an unnamed metering technology provider that had a malware-infected device on its network. The infostealer collected a large trove of credentials from that device, including passwords belonging to 167 US utility companies that rely on the provider. SpyCloud chief investigations officer Jason Lancaster said the single compromise effectively handed criminals the keys to "a hundred otherwise unrelated organizations," illustrating how one supplier's security lapse can cascade across the sector.
Distinct from the recent Iran-linked hacks
The research arrives weeks after a spate of intrusions against US water providers that the US government has privately attributed to Iran-backed hackers. SpyCloud said it found no evidence that those incidents relied on stolen passwords. Instead, the signs point to security weaknesses such as manufacturer-set default passwords in the mechanical switches and physical controllers used by critical infrastructure, a conclusion SpyCloud says echoes earlier findings from the US cybersecurity agency CISA.
Lancaster framed the situation as one where the water sector "has to hold both stories at once": vulnerable infrastructure hardware on one side, and stolen credentials circulating to whoever wants to buy or find them on the other.
Why it matters
Water providers sit at the intersection of public health and physical operations, and the systems flagged in this research control pumps and flows rather than just billing portals. The findings show that a commodity crime, infostealer infections on ordinary employee devices, can reach deep into critical infrastructure, and that multi-factor authentication is not a reliable backstop when session tokens are part of what gets stolen. The metering-vendor case adds a supply-chain dimension: utilities that secure their own networks can still be exposed through a trusted technology supplier. For a sector already contending with default-password flaws in its hardware, SpyCloud's numbers suggest compromised credentials are a parallel and equally accessible route in.
- #security
- #malware
- #critical-infrastructure
- #credentials
- #water-utilities