New research reveals that over a thousand U.S. water and wastewater providers are at risk of hacking due to malware that steals passwords. SpyCloud found that 1,787 organizations, nearly a fifth of those checked, have had their credentials compromised, including 250 that appear to give access to operational networks. These breaches could let hackers control physical pumps and water flows, posing a serious threat to infrastructure.
The findings come after a series of hacks targeting water providers, allegedly linked to Iran-backed hackers. However, SpyCloud found no evidence these particular hacks relied on stolen passwords, suggesting security weaknesses in the technology itself.
While password-stealing malware is not new, the ease with which it can access critical infrastructure is alarming. The stolen credentials can bypass multi-factor authentication, making them highly valuable to hackers. SpyCloud's database of over 66,000 public-facing systems registered with the U.S. Environmental Protection Agency highlights the widespread vulnerability.
The water sector must now navigate this complex landscape, balancing the threats from both stolen passwords and security weaknesses in critical infrastructure. The challenge lies in understanding that protecting water systems is not just about technology but also about the human factor.







