
Toxic Credentials: Stolen Passwords Expose American Water Utilities to Remote Cyber Attacks
New security research reveals that well over a thousand American water and wastewater providers remain dangerously exposed to cyber attacks because password-stealing malware harvested employee logins and active session tokens. Findings published by security firm SpyCloud highlight how easily criminal groups can compromise critical infrastructure across local communities.
While info-stealing malware is nothing new, the findings show how stolen credentials give attackers a direct doorway into municipal networks without writing custom exploits. SpyCloud compiled a database tracking more than 66,000 public-facing systems registered with the Environmental Protection Agency across 10,000 utility organizations. Analysts found password-stealing malware infected devices at 1,787 organizations, representing nearly two out of every ten providers analyzed.
At least 250 water providers had active credentials leaked online that allowed direct access to operational networks. These compromised remote-access portals control physical pumps, chemical treatments, and water flow levels.
The security analysis also covered a metering tech vendor that had infected hardware on its internal network. The malware collected massive logs of user credentials, including accounts tied to 167 public utility providers that rely on that specific vendor for daily monitoring. SpyCloud chief investigator Jason Lancaster stated that this single supply chain breach handed criminals direct access to a hundred otherwise unrelated utility networks.
Infostealer malware works by scraping stored web passwords and active session tokens directly from infected browser storage. These stolen session tokens allow hackers to hijack active user sessions without typing a password, often bypassing multi-factor authentication checks entirely. Criminals trade these stolen logs on dark web forums, selling access tokens to the highest bidder.
This report arrives shortly after a wave of targeted cyber attacks hit water providers across the country. Federal agencies previously linked several of those incidents to Iranian-backed hacker groups. While SpyCloud found no direct proof that those specific Iranian attacks used stolen passwords, investigators noted that many small facilities still rely on default factory passwords on mechanical controllers and remote switches.
Stolen credentials give malicious actors a cheap, quiet way into sensitive industrial controls. Municipal water districts often run on tight municipal budgets, leaving IT teams understaffed and unable to monitor active user sessions continuously. Small utility teams often lack automated tools to detect when an employee login originates from an unauthorized foreign IP address.
Protecting critical water infrastructure requires utilities to overhaul session management and credential hygiene immediately. Water operators must enforce strict multi-factor authentication, clear browser token storage, and invalidate active sessions whenever suspicious activity occurs. Securing municipal water supplies means locking down the everyday passwords and web sessions that keep local pumps running safely.







