New research shows that more than a thousand water and wastewater providers across the U.S. are vulnerable to cyberattacks due to password-stealing malware. The analysis reveals that this threat is not theoretical — attackers are already exploiting exposed credentials to gain access to critical infrastructure.
A cybersecurity firm analyzed over 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, covering roughly 10,000 organizations. It found that nearly 1,800 — about 18% — had credentials compromised by malware capable of stealing passwords and session tokens. At least 250 of those had exposed credentials that could allow remote access to operational networks controlling pumps, valves, and other water infrastructure systems.
One significant incident involved a metering technology vendor whose infected network leaked credentials linked to 167 U.S. utilities that rely on its services. That breach effectively handed attackers access to dozens of otherwise unrelated organizations via the same provider.
How the Malware Works
The malware identified in the study — often called an “infostealer” — doesn’t just capture stored passwords. It also retrieves session tokens, which let attackers impersonate valid users without needing to re-authenticate, potentially bypassing protections like multi-factor authentication. These stolen credentials are frequently traded on the dark web, enabling access to target organizations based on whoever acquires them.
The study also noted recent cyberattacks on U.S. water systems that have been attributed to Iran-backed hackers. However, in those cases the primary vulnerabilities were weak default passwords in physical controllers and network devices rather than infostealer malware. The firm found no evidence that the Iran-linked operations used credential theft through this malware in those incidents.
What This Means for Water Security
The findings underscore a growing risk that many water providers may not sufficiently secure credentials or monitor for how third-party vendors manage access. The exposed credentials represent pathways that attackers can exploit without needing to compromise devices physically or use more sophisticated tools.
The water sector is facing dual challenges: the known risk of weak defaults and misconfigured network devices, coupled with the rising threat from malware targeting login credentials and session tokens. Both vectors create entry points, and attackers will exploit whichever is easiest.
Addressing these risks requires more than patching devices. Water utilities must enforce stronger credential hygiene, monitor exports of credentials from partner networks, and assume that any third-party compromise might cascade into the operations of multiple providers.
Especially worrying is the scale. With nearly one in five water providers under threat, this isn’t about isolated incidents. The exposure stems from credential theft that spans vendor networks — a systemic vulnerability.
Why this matters: With water infrastructure foundational to public safety, health, and the economy, any breach can have outsized consequences. Unlike attacks on less critical networks, infiltrations into water control systems can disrupt supply, contaminate water, or even threaten lives. Regulatory pressure and technology investments will likely follow — companies will need to demonstrate visibility, accountability, and resilience in their cybersecurity practices.
What to watch for: announcements of new mandates or audits from agencies overseeing water utilities; public reports of vendor-related breaches; deployment of tools to monitor credential leaks and token misuse; and shifts in cybersecurity insurance practices for critical infrastructure.