Stolen passwords are exposing America’s water providers to hackers

1 hour ago 3
Image Credits:David McNew / Getty Images

8:50 AM PDT · September 22, 2026

New information probe has recovered that good implicit a 1000 U.S. h2o and wastewater providers are exposed to hacks owed to malware that’s susceptible of stealing their employees’ passwords and progressive logged-in sessions.

The findings by cybersecurity defence steadfast SpyCloud underscore however h2o providers and different captious infrastructure tin beryllium compromised with comparative easiness amidst a wave of hacks targeting the h2o supplies of dozens of communities crossed the United States.

While password-stealing malware is not new, the probe highlights however stolen passwords connection hackers an casual way to interruption into an organization’s web without utilizing AI tools.

SpyCloud said it built a database of much than 66,000 public-facing systems that are registered with the U.S. Environmental Protection Agency, amounting to 10,000 organizations. The institution recovered password-stealing malware had swiped passwords and credentials from 1,787 organizations, oregon astir 2 successful 10 providers they checked. The steadfast noted astatine slightest 250 organizations had credentials exposed that appeared to let entree to their operational networks and remote-access systems, which power the carnal pumps and h2o flows.

The investigation covered an unnamed metering tech provider, which had a instrumentality connected its web that was infected with password-stealing malware. The malware stole reams of credentials, including passwords for 167 U.S. inferior companies that trust connected the metering tech provider.

SpyCloud main investigations serviceman Jason Lancaster said in the post that this azygous breach handed criminals the keys to entree “a 100 different unrelated organizations.”

Password-stealing malware, besides known arsenic infostealers, let hackers to bargain a person’s stored passwords arsenic good arsenic the league tokens that are utilized to support them logged in. These league tokens tin let a hacker to log successful arsenic if they were the morganatic user, and tin often bypass multi-factor authentication systems. Hackers regularly commercialized stolen credentials successful bid to get passwords oregon league tokens for accessing circumstantial organizations.

This probe comes weeks aft a spate of hacks targeting h2o providers astir the United States, which the U.S. authorities has privately tied to Iran-backed hackers. SpyCloud said it recovered nary grounds that those Iran-linked hacks relied connected stolen passwords. In those cases, the signs constituent to information weaknesses, specified arsenic manufacturer-set default passwords, successful the mechanical switches and carnal controllers utilized by captious infrastructure, SpyCloud said, echoing earlier findings from U.S. cybersecurity bureau CISA. 

Rather, the researchers enactment that stolen passwords are a large root of entree to “whoever wants to bargain oregon find it,” successful parallel to the known information risks with captious infrastructure tech. Lancaster said that the water-sector “has to clasp some stories astatine once.”

When you acquisition done links successful our articles, we whitethorn gain a tiny commission. This doesn’t impact our editorial independence.

Zack Whittaker is the information exertion astatine TechCrunch. He besides authors the play cybersecurity newsletter, this week successful security.

He tin beryllium reached via encrypted connection astatine zackwhittaker.1337 connected Signal. You tin besides interaction him by email, oregon to verify outreach, astatine zack.whittaker@techcrunch.com.

Read Entire Article