SpyCloud: infostealer malware exposes 1,787 U.S. water utilities' passwords
New research finds stolen credentials, not just weak default passwords, offer hackers an easy route into water and wastewater systems.
What to know
- SpyCloud found infostealer malware had stolen credentials from 1,787 of about 10,000 U.S. water/wastewater organizations checked, nearly one in five.
- At least 250 organizations had exposed credentials that could reach operational networks and remote-access systems controlling physical pumps and water flows.
- A single infected device at one metering tech provider leaked credentials for 167 separate U.S. utility companies, showing how one compromise can cascade widely.
- This credential-theft threat is separate from the Iran-linked hacks exploiting default passwords in physical controllers, which SpyCloud says show no signs of relying on stolen credentials.
“whoever wants to buy or find it”
SpyCloud researchers, Cybersecurity researchers · TechCrunch ↗ · Sep 21
Jason Lancaster Chief Investigations Officer, SpyCloudSpyCloud Cybersecurity defense firmIran-backed hackers Alleged perpetrators of an earlier wave of water-utility hacksCISA U.S. cybersecurity agency
How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts
-
2
Coverage of the findings spreads across social platforms
The TechCrunch report was reshared on Mastodon, Bluesky, and Reddit with minimal added commentary, indicating pickup but little independent discussion.
-
1
SpyCloud separates stolen-password threat from Iran-linked hacks
SpyCloud said it found no evidence the earlier Iran-linked attacks relied on stolen passwords, framing infostealer-driven credential theft as a parallel, distinct risk to the sector's known default-password weaknesses.
“has to hold both stories at once…”
— Jason Lancaster, SpyCloud Chief Investigations Officer -
first by TechCrunch, 1d ago
-
T
Researchers say another looming threat hangs over some of America's most important critical infrastructure. https:// techcrunch.com/2026/09/22/stol en-passwords-are-exposing-americas-water-providers-to-hackers/?utm_source=dlvr.it&utm_medium=mastodon
-
-
background
SpyCloud reveals infostealer malware exposed 1,787 water utilities — SpyCloud built a database of more than 66,000 public-facing systems registered with the EPA across roughly 10,000 organizations, and found password-stealing malware had swiped credentials from 1,787 of them, with at least 250 exposures reaching operational networks and remote-access systems.
-
background
Iran-backed hackers hit U.S. water providers via default passwords — In the weeks before SpyCloud's report, a wave of hacks struck dozens of U.S. water provider communities; the U.S. government privately tied the intrusions to Iran-backed hackers exploiting manufacturer-set default passwords on mechanical switches and physical controllers, per CISA findings.