SpyCloud said Sept. 20 that stolen credentials connected to U.S. water-sector organizations are exposing a vendor-access risk, a finding that puts identity controls alongside plant-network security for utility operators.

What the research found

The cybersecurity company examined 10,000 organizations drawn from a database of 66,845 Environmental Protection Agency-registered water systems, including utilities and vendors. It reported active infostealer exposure at 1,787 of those organizations. Within the sample, 258 had credentials associated with operational technology or remote-access systems, while 263 faced active phishing or business-email-compromise targeting, according to SpyCloud’s research.

The report also describes an infected device at an advanced-metering vendor that contained saved logins for about 167 utility customer portals. Those are potential access paths, not a finding that the portals were entered. SpyCloud said it could not establish whether the credentials remained valid, what privileges they carried or whether anyone had used them.

TechCrunch reported on the findings Sept. 22, putting fresh attention on how a supplier’s compromised device could affect multiple utility customers. The research does not identify a confirmed breach of any water system from those credentials or tie the exposure to a particular threat actor.

The operational question for utilities

Water providers often depend on contractors for equipment, software and customer-facing services. That makes the access held by suppliers an operational issue for utilities even when a vendor’s laptop, rather than a plant controller, is the device initially compromised. The relevant question is whether saved credentials still grant entry, and whether the affected organizations can revoke them quickly.

The finding should not be read as proof that treatment systems were manipulated. SpyCloud distinguishes stolen identity data from direct exposure of plant-control equipment. Separately, federal water-system security guidance has urged operators to strengthen access controls and reduce internet exposure. That guidance provides context, not confirmation of an incident in this sample.

What utilities can do now

The research gives utility leaders a concrete vendor-review agenda: identify shared accounts, check remote access, rotate exposed passwords and establish who can disable a supplier’s credentials. Its counts are SpyCloud’s findings, not a sector-wide breach rate. For customers, the immediate public record supports concern about exposure and response readiness, not a claim that water service or safety has been affected.