Stolen passwords are exposing America’s water providers to hackers
- ID
- 27295
- Status
- summarized
- Published
- 22 Sep 2026, 11:50 PM
- Fetched
- 23 Sep 2026, 12:47 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/09/22/stolen-passwords-are-exposing-americas-water-providers-to-hackers/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 2.5
- Created
- 23 Sep 2026, 12:50 AM
- Tags
- Audience
- developers
What happened
SpyCloud research found that 1,787 of ~10,000 U.S. water and wastewater providers had credentials stolen by infostealer malware, with at least 250 having exposed credentials for operational networks controlling physical pumps and water flows. A single infected device at an unnamed metering tech provider leaked credentials for 167 unrelated utility companies, demonstrating supply-chain credential exposure.
Why it matters
The practical takeaway is about session token theft via infostealers — attackers bypass MFA by stealing active session cookies, not just passwords. If you build or operate systems with remote access to infrastructure, enforce session token rotation, device posture checks, and treat infostealer-compromised endpoints as a credential exposure event requiring forced re-authentication across all sessions. However, this is U.S. water-sector specific with no direct Malaysian or SEA infrastructure angle.
Discussion angle
The session-token-bypasses-MFA problem is the one detail worth discussing — how many of your own apps invalidate sessions after credential changes, and whether you'd even know if an employee's laptop was hit by an infostealer.