Static

Stolen passwords are exposing America’s water providers to hackers

First reported by TechCrunch ·

The signal ●○○○ Compiled by AI from TechCrunch, the single source so far
Why you might care

Stolen passwords for water utility systems are now readily available on the dark web, meaning attackers can bypass MFA and gain access.

What happened

New research from cybersecurity firm SpyCloud reveals that over 1,700 U.S. water and wastewater providers are vulnerable to cyberattacks due to stolen employee passwords and active login sessions. The firm analyzed over 66,000 public-facing systems registered with the EPA, finding that nearly 20% of these organizations had credentials compromised by password-stealing malware. At least 250 organizations had credentials exposed that could grant access to operational networks and remote-access systems controlling physical water infrastructure. A single breach at an unnamed metering tech provider exposed credentials for 167 utility companies, giving hackers access to numerous unrelated organizations. This research highlights a significant, easily exploitable vector for attackers targeting critical infrastructure, separate from recent direct attacks on water supplies that exploited default passwords.

What it means

The widespread compromise of credentials, facilitated by readily available password-stealing malware, exposes a critical vulnerability in the U.S. water sector. Unlike sophisticated attacks that might target specific systems, this method offers a low-barrier entry point for numerous threat actors. The ability of these tools to steal session tokens effectively bypasses multi-factor authentication, a common security measure, making the compromised credentials particularly potent. This reliance on stolen credentials presents a significant risk to the operational technology (OT) networks that control physical water processes, potentially leading to disruptions in service or even physical damage.

This research underscores a broader trend where basic credential theft remains a primary method for compromising critical infrastructure. While recent attacks on water providers have focused on exploiting device-level vulnerabilities, the prevalence of stolen passwords suggests a dual threat landscape. Organizations in the water sector must urgently re-evaluate their credential management practices and consider stricter controls and monitoring for remote access to OT environments. The findings also highlight the interconnectedness of the supply chain; a breach at a single vendor can have cascading effects across dozens of their clients.

AI-written summary. May contain errors.