SpyCloud Finds Credential Exposure Across US Water Providers

Cybersecurity firm SpyCloud has identified stolen passwords or credentials connected to 1,787 US water and wastewater organizations, nearly two in ten of the providers it examined. The research also found at least 250 organizations with exposed credentials that appeared to provide access to operational networks or remote-access systems used to control pumps and water flows.
The findings concern a sector that has faced a series of attacks on water supplies in communities across the United States. SpyCloud’s analysis points to a separate but overlapping access problem: malware that steals employee passwords and active login sessions can give criminals a route into an organization without exploiting a new technical vulnerability.
A broad inventory reveals credential risk
SpyCloud built a database of more than 66,000 public-facing systems registered with the US Environmental Protection Agency. Those systems represented 10,000 organizations. It then found evidence that password-stealing malware, often called infostealers, had captured passwords and credentials from 1,787 of them.
Infostealers collect stored passwords from infected devices and can also take session tokens. These tokens keep users logged in to services, so a stolen token may let an attacker act as the legitimate user and can, in some circumstances, bypass multi-factor authentication.
Stolen credentials are routinely traded by attackers looking for access to particular organizations. SpyCloud’s conclusion is therefore not limited to a single threat actor or campaign: exposed passwords and sessions can become an available access path for anyone able to obtain them.
Supplier compromise can widen the impact
The researchers highlighted an unnamed metering technology provider whose network included a device infected with password-stealing malware. The malware collected extensive credentials, including passwords for 167 US utility companies that use the provider’s technology.
Jason Lancaster, SpyCloud’s chief investigations officer, said that this one breach gave criminals the keys to a hundred otherwise unrelated organizations. The example illustrates how credentials held by a technology supplier can extend risk beyond the supplier’s own environment.
Credential theft is distinct from recent attacks
The report follows recent hacks of US water providers that the US government has privately linked to Iran-backed hackers. SpyCloud said it found no evidence that those incidents relied on stolen passwords.
Instead, signs in those attacks pointed to weaknesses such as manufacturer-set default passwords on mechanical switches and physical controllers, consistent with earlier findings by the Cybersecurity and Infrastructure Security Agency. Credential theft and insecure operational technology should therefore be treated as parallel exposure paths rather than competing explanations.
For water operators and their suppliers, the practical implication is to review access held by staff and third parties, act on exposed credentials, and address default passwords on reachable controllers. Protecting operational systems requires attention to both the identities that can enter the network and the devices that accept those identities.

