New cybersecurity research has revealed that over 1,000 U.S. water and wastewater providers are vulnerable to hacking due to malware designed to steal employee passwords and active login sessions. The findings come from SpyCloud, a cybersecurity firm, which highlighted the ease with which critical infrastructure, such as water systems, can be compromised. This comes amid a recent surge in hacking attempts targeting water supplies in communities across the United States. SpyCloud built a database of more than 66,000 public-facing systems registered with the U.S. Environmental Protection Agency, which are operated by about 10,000 organizations. The firm discovered that password-stealing malware had stolen credentials from 1,787 of these organizations, or nearly two in ten. Among these, at least 250 had credentials exposed that could provide access to their operational networks and remote systems controlling physical water pumps and flows. One of the affected systems was an unnamed metering technology provider, whose network had a device infected with the malware. This breach resulted in the theft of credentials, including passwords for 167 U.S. utility companies that use the metering tech provider’s services. Password-stealing malware, also known as infostealers, allows hackers to capture stored passwords and session tokens that keep users logged in. These tokens can enable hackers to log in as the legitimate user and may bypass multi-factor authentication systems. Stolen credentials are commonly traded on the dark web to gain access to specific organizations. This research follows a series of recent attacks on U.S. water providers, which the U.S. government has linked to hackers backed by Iran. However, SpyCloud found no evidence that these attacks used stolen passwords. Instead, the evidence points to vulnerabilities such as default passwords used in mechanical switches and physical controllers of critical infrastructure. This aligns with previous findings from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). SpyCloud’s chief investigations officer, Jason Lancaster, noted that the water sector must consider both the threat of stolen credentials and the risk of outdated or weak default passwords. He emphasized that the sector must address both issues simultaneously to strengthen its defenses against cyber threats.