<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/stolen-passwords-are-exposing-america-s-water-providers-to-hackers-9zsy7abhk" -->

---
title: Stolen passwords are exposing America’s water providers...
description: New research from cybersecurity firm SpyCloud found that infostealer malware has compromised passwords and session tokens at 1,787 U.S. water and wastewater...
canonical: https://daily.dev/posts/stolen-passwords-are-exposing-america-s-water-providers-to-hackers-9zsy7abhk
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Stolen passwords are exposing America’s water providers to hackers | daily.dev
og:description: New research from cybersecurity firm SpyCloud found that infostealer malware has compromised passwords and session tokens at 1,787 U.S. water and wastewater...
og:url: https://daily.dev/posts/stolen-passwords-are-exposing-america-s-water-providers-to-hackers-9zsy7abhk
og:image: https://api.daily.dev/og/posts/9ZSy7AbHk.png
og:image:alt: Stolen passwords are exposing America’s water providers to hackers
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Stolen passwords are exposing America’s water providers to hackers

**[TechCrunch](https://daily.dev/sources/tc)** · 3 min read · 0 upvotes · 0 comments

## Summary

New research from cybersecurity firm SpyCloud found that infostealer malware has compromised passwords and session tokens at 1,787 U.S. water and wastewater organizations out of roughly 10,000 checked, with at least 250 having credentials exposed that could grant access to operational networks controlling pumps and water flows. A single infected device at an unnamed metering technology provider exposed credentials for 167 utility companies that rely on it, illustrating how one breach can cascade across many unrelated organizations. Separately, ongoing Iran-linked attacks on water utilities appear to exploit default passwords on physical controllers rather than stolen credentials, meaning the sector faces two distinct but simultaneous threats.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://techcrunch.com/2026/09/22/stolen-passwords-are-exposing-americas-water-providers-to-hackers>

## Questions this post answers

### How many US water utilities have had passwords stolen by infostealer malware?

Security research identified 1,787 water and wastewater organizations with credentials stolen by password-stealing malware, out of about 10,000 organizations checked across 66,000 public-facing systems registered with the EPA. At least 250 of those organizations had exposed credentials that appeared to grant access to operational networks and remote-access systems controlling pumps and water flows.

_Track infrastructure security research like this on daily.dev to stay ahead of utility sector threats._

### How did one infected device expose credentials for over 100 water utilities at once?

A device belonging to an unnamed metering technology provider was infected with password-stealing malware, which harvested credentials for 167 U.S. utility companies that relied on that provider's technology. SpyCloud's chief investigations officer described this single breach as handing criminals the keys to roughly a hundred otherwise unrelated organizations, illustrating the cascading risk of third-party vendor compromises.

_Developers securing vendor integrations can follow supply-chain risk coverage on daily.dev._

### Are the Iran-linked hacks on US water utilities caused by stolen passwords?

No, SpyCloud found no evidence that Iran-linked attacks on US water utilities relied on stolen passwords. Instead, those intrusions appear tied to security weaknesses like manufacturer-set default passwords on mechanical switches and physical controllers, a finding consistent with earlier warnings from CISA, meaning stolen credentials and weak default configurations are two separate risks facing the sector simultaneously.

_Follow ongoing critical infrastructure threat reporting on daily.dev to separate distinct attack vectors._

## Similar posts on daily.dev

- [What we know about the alleged Iranian hacks on US water utilities](https://daily.dev/posts/what-we-know-about-the-alleged-iranian-hacks-on-us-water-utilities-ppbezomds) · TechCrunch · 21 upvotes · 3 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#authentication](https://daily.dev/tags/authentication), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/stolen-passwords-are-exposing-america-s-water-providers-to-hackers-9zsy7abhk)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Stolen passwords are exposing America’s water providers to hackers","url":"https://daily.dev/posts/stolen-passwords-are-exposing-america-s-water-providers-to-hackers-9zsy7abhk","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/stolen-passwords-are-exposing-america-s-water-providers-to-hackers-9zsy7abhk"},"datePublished":"2026-09-22T15:54:55.335Z","dateModified":"2026-09-22T15:55:21.712Z","description":"New research from cybersecurity firm SpyCloud found that infostealer malware has compromised passwords and session tokens at 1,787 U.S. water and wastewater...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e8069b2d2172ccda386116e107623f54?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e8069b2d2172ccda386116e107623f54?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"TechCrunch","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"TechCrunch","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tc","url":"https://daily.dev/sources/tc"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/stolen-passwords-are-exposing-america-s-water-providers-to-hackers-9zsy7abhk","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,authentication,malware","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"TechCrunch","item":"https://daily.dev/sources/tc"},{"@type":"ListItem","position":3,"name":"Stolen passwords are exposing America’s water providers to hackers"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/stolen-passwords-are-exposing-america-s-water-providers-to-hackers-9zsy7abhk#faq","mainEntity":[{"@type":"Question","name":"How many US water utilities have had passwords stolen by infostealer malware?","acceptedAnswer":{"@type":"Answer","text":"Security research identified 1,787 water and wastewater organizations with credentials stolen by password-stealing malware, out of about 10,000 organizations checked across 66,000 public-facing systems registered with the EPA. At least 250 of those organizations had exposed credentials that appeared to grant access to operational networks and remote-access systems controlling pumps and water flows. Track infrastructure security research like this on daily.dev to stay ahead of utility sector threats."}},{"@type":"Question","name":"How did one infected device expose credentials for over 100 water utilities at once?","acceptedAnswer":{"@type":"Answer","text":"A device belonging to an unnamed metering technology provider was infected with password-stealing malware, which harvested credentials for 167 U.S. utility companies that relied on that provider's technology. SpyCloud's chief investigations officer described this single breach as handing criminals the keys to roughly a hundred otherwise unrelated organizations, illustrating the cascading risk of third-party vendor compromises. Developers securing vendor integrations can follow supply-chain risk coverage on daily.dev."}},{"@type":"Question","name":"Are the Iran-linked hacks on US water utilities caused by stolen passwords?","acceptedAnswer":{"@type":"Answer","text":"No, SpyCloud found no evidence that Iran-linked attacks on US water utilities relied on stolen passwords. Instead, those intrusions appear tied to security weaknesses like manufacturer-set default passwords on mechanical switches and physical controllers, a finding consistent with earlier warnings from CISA, meaning stolen credentials and weak default configurations are two separate risks facing the sector simultaneously. Follow ongoing critical infrastructure threat reporting on daily.dev to separate distinct attack vectors."}}]}
```

