Stolen passwords are exposing America’s water providers to hackers

New research by SpyCloud indicates that over a thousand U.S. water and wastewater providers are vulnerable to cyberattacks due to employees' stolen passwords and active login sessions. Password-stealing malware, or infostealers, have compromised credentials for 1,787 organizations, with 250 having direct access to operational networks, posing a significant threat to critical infrastructure.
Why it matters
The findings expose a critical vulnerability in essential U.S. infrastructure, highlighting the ease with which hackers can disrupt vital services and the urgent need for enhanced cybersecurity measures to protect public utilities.
New security research has found that well over a thousand U.S. water and wastewater providers are exposed to hacks due to malware that’s capable of stealing their employees’ passwords and active logged-in sessions.
The findings by cybersecurity defense firm SpyCloud underscore how water providers and other critical infrastructure can be compromised with relative ease amidst a wave of hacks targeting the water supplies of dozens of communities across the United States.
While password-stealing malware is not new, the research highlights how stolen passwords offer hackers an easy route to break into an organization’s network without using AI tools.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in