258 U.S. Water Organizations Have Credentials Exposed to Infostealers

water system

Threat actors have found a new entry point into water systems. Image: SELİM ARDA ERYILMAZ/Unsplash

SpyCloud found stolen credentials linked to OT and remote-access systems across U.S. water utilities, exposing another potential route for attackers.

Sep 23, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

U.S. water utilities already have to worry about hackers targeting industrial equipment exposed to the internet. Stolen employee and vendor credentials may give attackers another way in.

SpyCloud says 1,787 organizations connected to the U.S. water and wastewater sector show exposure to infostealer malware, including 258 with compromised credentials associated with operational technology or remote-access systems.

While the research confirms the central theme of the FBI and CISA’s warnings, it does not link its findings to the named actors in the FBI’s report.

Still, the timing puts a serious security problem under the spotlight. Recent incidents show how exposed industrial systems can be to direct targeting while stolen credentials create a separate entry path.

One infrastructure; multiple attack channels

In July, the FBI released a public service announcement (PSA) with the Environmental Protection Agency (EPA) noting that threat actors are increasingly targeting U.S. water systems across several states to cause disruptions. The PSA cited an attack on internet-facing systems and their controllers, a technique similar to one used in an earlier attack on fuel gauging systems.

But direct attacks on exposed industrial systems are not the only route into these organizations.

In its Sept. 20 report, SpyCloud noted that the threat has moved into credential theft. After analyzing 10,000 organizations connected to the U.S. water and wastewater sector, SpyCloud found that 1,787 had active exposure from infostealer malware.

More concerning, SpyCloud identified 258 organizations with exposed credentials associated with OT or remote-access systems. If those credentials remain valid, they could provide attackers with a potential route toward systems supporting physical water operations, extending the risk beyond compromised employee accounts.

Per SpyCloud's research, that exposure can begin with an employee or vendor device becoming infected, including through phishing or credentials obtained in previous data breaches.

The vendor risk makes this newly discovered exposure harder to contain. SpyCloud said it found one infected device belonging to an unnamed water-metering technology provider containing logins affiliated with about 167 U.S. utility companies, meaning a single compromised third party could expose access to many separate utilities. 

Advertisement

The risk also extends beyond passwords. SpyCloud said infostealer infections can expose authentication material such as session tokens, potentially allowing attackers to hijack an already authenticated session without triggering a new MFA challenge.

That matters because MFA alone cannot contain every form of identity compromise. Defenders also need controls capable of detecting stolen sessions, unusual logins, compromised endpoints, and unexpected access to sensitive systems.

Why operational disruptions are a different kind of cyber threat

Credential theft is damaging in any organization, but the consequences change when compromised accounts provide a route toward operational technology.

Water utilities depend on connected systems to monitor and control processes such as pumping, treatment, pressure, and distribution. An attacker who moves from a compromised identity into those environments could potentially disrupt physical operations rather than simply steal data.

That possibility is why the FBI and other federal agencies have repeatedly emphasized protecting internet-facing industrial systems and limiting remote access to critical infrastructure.

That makes operational disruptions — and the need to prevent them — much more serious.

What can be done

No utility can eliminate every credential compromise. The more realistic goal is to keep one stolen account or infected vendor device from becoming a path to operational systems — and to keep essential services running if an intrusion does occur.

To mitigate these risks, critical utilities should implement the following defenses:

  • Where remote access is needed, require MFA for vendor and maintenance accounts, and use phishing-resistant methods where possible.
  • Train employees on cybersecurity best practices, including how to detect phishing attacks.
  • Organizations should regularly check credential databases for leaked credentials and data that attackers may use for further attacks.
  • Segment IT and OT networks and give accounts only the access they actually need, limiting how far an attacker can move after compromising one account.
  • Monitor remote logins and unusual account activity, keep systems patched, and maintain an up-to-date inventory of connected assets, including third-party systems.
  • Prepare for compromise with tested incident-response, redundancy, and recovery plans to keep critical processes operating if connected systems are breached.
Advertisement

MFA remains an important defense, but stolen sessions, compromised endpoints, and third-party access can create ways around account-level protections. For water utilities, the larger objective is containment: one stolen identity should not become a route to the systems controlling pumps, treatment processes, or water distribution.

The SpyCloud findings reinforce why identity security and OT security can no longer be treated as separate problems. Protecting the infrastructure increasingly means protecting the credentials that lead to it.

Other news: A recent Gyazo breach exposed 23.62 million user records and 490 million image metadata records, potentially revealing email addresses, password hashes, IP addresses, location data, OCR-extracted text, and image IDs.

Joseph Chisom Ofonagoro

Joseph is a Technical Writer with about 3 years of experience in the industry, also advancing a career in cyber threat intelligence. He is passionate about the responsible use of technology, a passion that led him into cybersecurity. As an undergrad, he leads a novel community of technology enthusiasts at his school, NOUN, where he guides and shares resources for beginners in tech. His writing experience includes a diverse range of topics, from consumer tech to startups to tutorials. Additionally, he periodically shares case studies and research reports on cybersecurity on his social media pages.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.