SpyCloud analyzed 10,000 organizations registered with the Environmental Protection Agency, discovering that nearly one in five had credentials compromised by malware. At least 250 of these entities face immediate risk, as the stolen data includes access keys for remote systems that govern physical water pumps and flow controls. The threat extends through the supply chain; a single breach at one metering technology provider exposed login credentials for 167 distinct utility companies.
In section Startups & Technology
Stolen credentials expose US water infrastructure to cyberattack
More than 1,700 U.S. water and wastewater providers are currently vulnerable to cyber intrusion, according to research from cybersecurity firm SpyCloud. The study reveals that infostealer malware has successfully harvested employee passwords and active session tokens, providing unauthorized actors with direct paths into sensitive operational networks.

Infostealers bypass traditional security barriers by capturing session tokens, which allow attackers to impersonate legitimate users and often circumvent multi-factor authentication. Jason Lancaster, chief investigations officer at SpyCloud, noted that this allows criminals to gain access to numerous unrelated organizations through one point of failure. While recent high-profile water sector attacks have been linked to Iran-backed actors exploiting default manufacturer passwords, these findings indicate that stolen credentials represent a separate, equally pervasive vector for infiltration. Operators now face the dual challenge of hardening physical controllers while securing the digital identities of their workforce.
Comments (0)
No comments yet. Be the first!