Infostealer malware compromises credentials at hundreds of U.S. water utilities

SpyCloud research found that password-stealing malware has exposed credentials from over 1,700 U.S. water and wastewater organizations, with at least 250 having access to operational networks. A single infected metering tech provider leaked passwords for 167 utilities, giving hackers an easy entry point. The findings highlight how stolen credentials can bypass security without relying on AI tools.
SpyCloud's analysis drew from a database of over 66,000 public-facing systems registered with the EPA, spanning roughly 10,000 organizations. The firm determined that nearly one in five providers examined had credentials lifted by infostealer malware, with at least 250 showing exposed credentials tied to operational networks and remote-access systems that govern physical infrastructure like pumps and water flow controls.
Infostealers operate by harvesting stored passwords and active session tokens, which let attackers impersonate legitimate users and often circumvent multi-factor authentication. Stolen credentials are routinely traded among hackers seeking access to specific targets. Notably, SpyCloud found no connection between these credential thefts and recent Iran-linked attacks on water utilities, which instead exploited default manufacturer passwords in physical controllers.
This research suggests that water utilities face a persistent, low-barrier threat that may not require sophisticated tools or AI assistance. Communities served by these providers could experience service disruptions or safety risks if attackers leverage stolen credentials to manipulate water systems. The findings may pressure smaller utilities to reassess vendor relationships and credential hygiene, potentially reshaping how the sector approaches cybersecurity investments and third-party risk management.