AI Weekly Malaysia

Back to items Summaries

Stolen passwords are exposing America’s water providers to hackers

ID
27295
Status
summarized
Published
22 Sep 2026, 11:50 PM
Fetched
23 Sep 2026, 12:47 AM
Provider
TechCrunch
Category
technology
Original URL
https://techcrunch.com/2026/09/22/stolen-passwords-are-exposing-americas-water-providers-to-hackers/
Source URL
https://techcrunch.com/feed/

Summary

Score
2.5
Created
23 Sep 2026, 12:50 AM
Tags
Audience
developers

What happened

SpyCloud research found that 1,787 of ~10,000 U.S. water and wastewater providers had credentials stolen by infostealer malware, with at least 250 having exposed credentials for operational networks controlling physical pumps and water flows. A single infected device at an unnamed metering tech provider leaked credentials for 167 unrelated utility companies, demonstrating supply-chain credential exposure.

Why it matters

The practical takeaway is about session token theft via infostealers — attackers bypass MFA by stealing active session cookies, not just passwords. If you build or operate systems with remote access to infrastructure, enforce session token rotation, device posture checks, and treat infostealer-compromised endpoints as a credential exposure event requiring forced re-authentication across all sessions. However, this is U.S. water-sector specific with no direct Malaysian or SEA infrastructure angle.

Discussion angle

The session-token-bypasses-MFA problem is the one detail worth discussing — how many of your own apps invalidate sessions after credential changes, and whether you'd even know if an employee's laptop was hit by an infostealer.

Top