Home / Technology / Malware Exposes 1,787 US Water Providers to Cyberattacks
Malware Exposes 1,787 US Water Providers to Cyberattacks
22 Sep
Summary
- Over 1,700 US water providers are vulnerable to hacks via stolen passwords.
- Malware can steal passwords and active logged-in sessions.
- Stolen credentials provide easy access to operational networks and controls.

New security research indicates that more than 1,700 U.S. water and wastewater providers face significant cyber risks. Malware has been found capable of stealing employees' passwords and active logged-in sessions, exposing these critical infrastructure entities to potential hacks. Cybersecurity firm SpyCloud discovered that nearly two in ten water providers checked had credentials compromised by password-stealing malware.
These stolen credentials offer hackers a straightforward method to infiltrate an organization's network. At least 250 of the affected organizations had credentials exposed that seemingly grant access to their operational networks and remote-access systems. These systems are crucial for controlling physical pumps and water flows.
Password-stealing malware, also known as infostealers, can pilfer stored passwords and session tokens. Session tokens are particularly concerning as they can allow hackers to impersonate legitimate users, often bypassing multi-factor authentication. Criminals frequently trade these stolen credentials, enabling access to specific organizations.
This research emerges amidst a series of recent hacks targeting water providers across the United States. While some of these recent attacks have been privately linked to Iran-backed hackers and exploit security weaknesses like default passwords, SpyCloud's findings suggest a broader threat from stolen credentials available on the cybercriminal market.