Stolen Passwords Put US Water Systems Back in Danger

Hackers don't always need a zero-day to attack critical infrastructure. Sometimes they just need somebody's saved password.

New research from cybersecurity company SpyCloud found stolen credentials associated with 1,787 U.S. water and wastewater organizations, representing nearly two in 10 of the providers it examined.

More concerning, SpyCloud identified at least 250 organizations with exposed credentials that appeared capable of reaching operational networks or remote-access systems connected to physical pumps and water flows.

The findings expose a familiar cybersecurity problem inside infrastructure where failure can have very physical consequences.

Infostealers are boring — and that's the problem

The malware involved isn't exotic.

Information-stealing malware, often called an infostealer, infects a computer and harvests information including:

saved passwords,

browser credentials,

cookies,

and active session tokens.

Those session tokens are especially valuable because they can sometimes let attackers impersonate an already authenticated user, bypassing the normal login process and even some multifactor-authentication protections.

No advanced exploit is necessary.

The attacker logs in with information the real employee already provided.

One infected supplier can spread risk across dozens of utilities

SpyCloud's research included an unnamed technology vendor serving water utilities.

A device associated with that provider was infected with password-stealing malware.

The stolen information included credentials linked to 167 U.S. utility companies that relied on the vendor.

That is a classic supply-chain problem.

The attacker does not necessarily need to compromise 167 organizations individually.

Compromise one business sitting in the middle and the potential attack surface expands dramatically.

Modern infrastructure relies heavily on vendors for metering, remote monitoring, software and maintenance.

Each connected supplier becomes another identity that has to be secured.

Critical infrastructure often mixes old technology with remote access

Water utilities present a difficult cybersecurity environment.

Many operate physical equipment designed to remain in service for years or decades.

At the same time, operators increasingly need remote access to monitor and manage those systems efficiently.

That combination creates tension.

Operational technology may be old.

Remote-access systems are connected.

Employee credentials can be stolen from comparatively ordinary computers.

A compromise that begins inside a web browser can therefore create a path toward systems controlling physical infrastructure.

Password theft can bypass expensive security

Organizations spend heavily on firewalls, endpoint detection and multifactor authentication.

Those controls matter.

But attackers increasingly target identity itself.

If they obtain a legitimate employee's active session, a security platform may initially see activity coming from someone who appears already authenticated.

This is why modern security increasingly focuses not only on login events but on what happens afterward.

Is the user accessing an unusual system?

Downloading more information than normal?

Connecting from an unexpected location?

Attempting to reach industrial controls they have rarely touched before?

Credentials prove who someone claims to be.

Behavior helps determine whether that claim should still be trusted.

Water infrastructure has already attracted attackers

The findings arrive amid heightened concern about attacks targeting U.S. water systems.

TechCrunch notes a recent wave of incidents affecting community water providers, while U.S. authorities have previously warned about weaknesses including default manufacturer passwords and exposed industrial equipment.

SpyCloud said it did not find evidence that the recent Iran-linked incidents referenced in its research relied on the stolen credentials it identified.

That distinction matters.

The study describes another potential entry path, not necessarily the mechanism behind those separate attacks.

Small utilities have a resource problem

Large banks or technology companies can employ substantial security teams.

A small regional water provider may not have that luxury.

Yet the systems it operates are critical.

That imbalance makes infrastructure cybersecurity especially difficult.

Attackers only need one weak account.

Defenders have to secure every account, vendor and remote-access point.

The economics favor the attacker.

What happens next?

Water providers need stronger identity controls, but the broader lesson applies across critical infrastructure.

Organizations should assume some employee passwords and session tokens will eventually be stolen.

Security therefore cannot end at authentication.

Access needs to be continuously evaluated.

Sensitive networks need segmentation.

Third-party accounts need strict limits.

Old credentials need to disappear quickly.

And operational systems should never be reachable simply because someone successfully reproduced a password from a browser.

Critical infrastructure cybersecurity often sounds like a battle against nation-state hacking tools.

SpyCloud's findings offer a less dramatic warning.

Sometimes the route to a physical control system begins with ordinary malware stealing an ordinary password.

Our latest news