SpyCloud Finds Stolen Passwords Expose 1,787 US Water Organizations
SpyCloud found stolen credentials at 1,787 U.S. water organizations, including at least 250 with access directly tied to pumps, flows and remote systems.
Summary
On September 22, 2026, SpyCloud said infostealers had compromised credentials from 1,787 of 10,000 U.S. water and wastewater organizations examined, nearly two in 10. Its database covered more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency. At least 250 organizations had exposed credentials apparently linked to operational networks or remote-access systems controlling pumps and water flows. Infostealers capture stored passwords and active session tokens, which criminals trade and can use to impersonate employees, often bypassing multi-factor authentication without AI tools.
One infected device at an unnamed metering technology provider surrendered credentials for 167 U.S. utility companies using its services. SpyCloud Chief Investigations Officer Jason Lancaster said that single compromise created access paths into 100 otherwise unrelated organizations. Separate recent attacks affected water providers in dozens of U.S. communities and were privately attributed by the U.S. government to Iran-backed hackers, but SpyCloud found no evidence stolen credentials enabled them. Instead, manufacturer-set default passwords in mechanical switches and physical controllers appear implicated, matching earlier CISA findings. Water operators therefore face parallel risks from tradable credentials and insecure infrastructure technology.
Positives
- SpyCloud mapped more than 66,000 EPA-registered public-facing systems across 10,000 organizations, giving defenders a broad view of credential exposure.
- At least 250 organizations with credentials linked to operational or remote-access systems can now prioritize those potentially consequential exposures.
- SpyCloud found no evidence that stolen passwords enabled the recent attacks privately attributed to Iran-backed hackers.
- CISA and SpyCloud findings identify manufacturer-set default passwords as a separate, concrete weakness affecting infrastructure controllers.
Risks & concerns
- Infostealers compromised credentials from 1,787 water and wastewater organizations, nearly two in 10 examined.
- At least 250 organizations exposed credentials apparently connected to systems controlling physical pumps and water flows.
- One infected device at an unnamed metering provider leaked credentials belonging to 167 U.S. utility companies.
- Stolen session tokens can let attackers impersonate legitimate users and often bypass multi-factor authentication.
- Criminal markets make stolen passwords and sessions available to attackers seeking access to specific organizations.
- Recent attacks affected water providers across dozens of U.S. communities, while default passwords remain another route into critical systems.