Stolen Credentials Exposed 1,787 U.S. Water Providers

Malware-captured logins threaten operational and remote-access systems at hundreds of critical utility facilities.

Updated on Oct. 11, 2026 in Cybersecurity

Stolen Credentials Exposed 1,787 U.S. Water Providers

Live Poll

Do you trust that your local water utility has adequate cybersecurity measures in place?

Researchers identified 1,787 U.S. water and wastewater organizations with compromised credentials, including passwords and active session tokens. The analysis found that nearly 20% of the examined providers face exposure through infostealer malware.

Why it matters

The widespread availability of these credentials on underground marketplaces enables unauthorized access to critical operational networks. This threat persists because stolen session tokens allow attackers to bypass multi-factor authentication mechanisms.

Researchers analyzed 66,000 systems registered with the EPA, identifying 250 organizations with exposed credentials for operational and remote-access networks. Additionally, one unnamed metering technology vendor compromise accounted for the exposure of 167 utility companies.

The players

SpyCloud

A cybersecurity firm specializing in identity analytics and the monitoring of data breached from infostealer malware.

Environmental Protection Agency

The federal regulatory body responsible for environmental standards and oversight of publicly accessible water utility systems.

The details

Infostealer malware operates by harvesting saved passwords and active session tokens directly from user browsers, allowing attackers to hijack existing logins and circumvent multi-factor authentication. These stolen files are then traded on underground marketplaces, granting illicit entry to industrial control and administrative networks. The vulnerability is amplified by shared reliance on third-party metering software, where a single point of failure can lead to cascading credential exposure across dozens of utilities.

Timeline

  1. October 11, 2026: The report identifying these compromised credentials was published.

The Tech Race

This report highlights a shifting defensive landscape where infrastructure security relies less on perimeter firewalls and more on identity integrity. It follows patterns established by recent CISA warnings regarding the increasing sophistication of credential theft in critical utility sectors.

Utility providers must address exposure by forcing credential rotations and auditing remote-access permissions for third-party software. These findings signal that IT teams should prioritize session token revocation to mitigate the risk posed by captured browser data.

The takeaway

The ubiquity of infostealer malware has transformed saved browser passwords into a primary vector for infrastructure disruption. Stakeholders should monitor upcoming guidance from the EPA regarding the security auditing of third-party metering vendors.

Further reading

For more on how infrastructure is defending against identity-based threats, explore our coverage in Cybersecurity.

Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.

Live Poll

Do you trust that your local water utility has adequate cybersecurity measures in place?