← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Over 1,700 US Water Providers Exposed to Hacks via Stolen Employee Passwords

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 1,787 U.S. water providers compromised by infostealers.
  • 250 organizations had credentials for operational networks exposed.
  • A metering tech provider breach exposed 167 utility companies.
  • Infostealers bypass multi-factor authentication via session tokens.

Widespread Credential Compromise

Cybersecurity firm SpyCloud identified that 1,787 U.S. water and wastewater providers, representing nearly 20% of those checked, have been affected by password-stealing malware. This malware compromises employee passwords and active logged-in sessions, creating an entry point for hackers into critical infrastructure systems.

The research covered over 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, encompassing 10,000 organizations. Among the compromised, at least 250 organizations had credentials exposed that could grant access to their operational networks and remote-access systems, which control physical water pumps and flows.

Impact of a Third-Party Breach

An analysis highlighted a specific incident involving an unnamed metering technology provider. A device on this provider's network was infected with password-stealing malware, leading to the theft of credentials for 167 U.S. utility companies that rely on its services. SpyCloud's Chief Investigations Officer, Jason Lancaster, stated that this single breach provided criminals with access to numerous unrelated organizations.

How Password-Stealing Malware Works

Password-stealing malware, also known as infostealers, captures stored passwords and session tokens. Session tokens allow hackers to bypass multi-factor authentication and log in as legitimate users. Stolen credentials are frequently traded among hackers to gain access to specific organizations.

Context Amid Recent Attacks

This research follows recent hacks targeting U.S. water providers, which the U.S. government has attributed to Iran-backed actors. However, SpyCloud found no evidence that these specific Iran-linked attacks utilized stolen passwords. Instead, those incidents pointed to security weaknesses such as manufacturer-set default passwords in mechanical switches and physical controllers.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

New research by SpyCloud reveals that 1,787 U.S. water and wastewater providers have had employee passwords and active logged-in sessions compromised by password-stealing malware. This exposure allows hackers to access operational networks and remote-access systems, posing a risk to critical infrastructure.