conv.

All stories
SecurityActive · 38h

SpyCloud: infostealer malware exposes 1,787 U.S. water utilities' passwords

New research finds stolen credentials, not just weak default passwords, offer hackers an easy route into water and wastewater systems.

What to know

  • SpyCloud found infostealer malware had stolen credentials from 1,787 of about 10,000 U.S. water/wastewater organizations checked, nearly one in five.
  • At least 250 organizations had exposed credentials that could reach operational networks and remote-access systems controlling physical pumps and water flows.
  • A single infected device at one metering tech provider leaked credentials for 167 separate U.S. utility companies, showing how one compromise can cascade widely.
  • This credential-theft threat is separate from the Iran-linked hacks exploiting default passwords in physical controllers, which SpyCloud says show no signs of relying on stolen credentials.

“whoever wants to buy or find it”

SpyCloud researchers, Cybersecurity researchers · TechCrunch ↗ · Sep 21

Jason Lancaster Chief Investigations Officer, SpyCloudSpyCloud Cybersecurity defense firmIran-backed hackers Alleged perpetrators of an earlier wave of water-utility hacksCISA U.S. cybersecurity agency

SpyCloud: infostealer malware exposes 1,787 U.S. water utilities' passwords
techcrunch.com

How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts

Peak 3 pieces in one hour at Sep 22, 10 AM; 9 pieces over 39 hours (1 article · 8 posts) Sep 22, 10 AM — 3 pieces · 1 article · 2 posts — Mastodon 2, Newswires 1Sep 22, 11 AM — 3 pieces · 3 posts — Bluesky 3Sep 22, 12 PM — quietSep 22, 1 PM — quietSep 22, 2 PM — quietSep 22, 3 PM — quietSep 22, 4 PM — quietSep 22, 5 PM — 1 piece · 1 post — Reddit 1Sep 22, 6 PM — quietSep 22, 7 PM — quietSep 22, 8 PM — quietSep 22, 9 PM — quietSep 22, 10 PM — quietSep 22, 11 PM — quietYesterday, 12 AM — quietYesterday, 1 AM — quietYesterday, 2 AM — quietYesterday, 3 AM — quietYesterday, 4 AM — quietYesterday, 5 AM — quietYesterday, 6 AM — quietYesterday, 7 AM — quietYesterday, 8 AM — quietYesterday, 9 AM — quietYesterday, 10 AM — 1 piece · 1 post — Bluesky 1Yesterday, 11 AM — quietYesterday, 12 PM — quietYesterday, 1 PM — 1 piece · 1 post — Bluesky 1Yesterday, 2 PM — quietYesterday, 3 PM — quietYesterday, 4 PM — quietYesterday, 5 PM — quietYesterday, 6 PM — quietYesterday, 7 PM — quietYesterday, 8 PM — quietYesterday, 9 PM — quietYesterday, 10 PM — quietYesterday, 11 PM — quietToday, 12 AM — quiet 1–2
4 PMyesterday8 AM4 PMnow · 1:58 AM ET
  1. 2

    Coverage of the findings spreads across social platforms

    The TechCrunch report was reshared on Mastodon, Bluesky, and Reddit with minimal added commentary, indicating pickup but little independent discussion.

  2. 1

    SpyCloud separates stolen-password threat from Iran-linked hacks

    SpyCloud said it found no evidence the earlier Iran-linked attacks relied on stolen passwords, framing infostealer-driven credential theft as a parallel, distinct risk to the sector's known default-password weaknesses.

    “has to hold both stories at once…”
    — Jason Lancaster, SpyCloud Chief Investigations Officer
    1. first by TechCrunch, 1d ago

    • TechCrunch@mstdn.social

      Researchers say another looming threat hangs over some of America's most important critical infrastructure. https:// techcrunch.com/2026/09/22/stol en-passwords-are-exposing-americas-water-providers-to-hackers/?utm_source=dlvr.it&utm_medium=mastodon

      TechCrunch@mstdn.socialMastodon1d agoview on Mastodon ↗
  3. background

    SpyCloud reveals infostealer malware exposed 1,787 water utilities — SpyCloud built a database of more than 66,000 public-facing systems registered with the EPA across roughly 10,000 organizations, and found password-stealing malware had swiped credentials from 1,787 of them, with at least 250 exposures reaching operational networks and remote-access systems.

  4. background

    Iran-backed hackers hit U.S. water providers via default passwords — In the weeks before SpyCloud's report, a wave of hacks struck dozens of U.S. water provider communities; the U.S. government privately tied the intrusions to Iran-backed hackers exploiting manufacturer-set default passwords on mechanical switches and physical controllers, per CISA findings.

What people are saying 0 voices from 0 sites · best of 2 · verbatim