Nearly 1,800 Water Utilities Found Exposed to Infostealer Malware

A new report from security firm SpyCloud has identified active infostealer malware exposure across nearly 1,800 water systems and utilities registered with the Environmental Protection Agency (EPA). The findings, reported exclusively by CyberScoop, add a new dimension to long-standing concerns about the cybersecurity of America's water infrastructure: one rooted not in aging industrial control systems, but in stolen employee and vendor credentials quietly circulating on criminal marketplaces.

Infostealer malware is designed to sit on a device, often after a user clicks a malicious link or downloads a compromised file, and siphon off saved passwords, browser cookies, autofill data, and authentication tokens. That stolen information is then packaged and sold or traded among cybercriminals. According to SpyCloud's analysis, the scale of exposure among water utilities is widespread enough to suggest a systemic supply chain risk rather than a handful of isolated incidents.

Why Infostealer Exposure Is a Privacy Problem, Not Just a Security One

Most coverage of water system cybersecurity focuses on operational risk: the possibility that hackers could manipulate pumps, valves, or treatment chemicals. That risk is real and well documented. But the SpyCloud findings highlight a quieter, equally serious problem: the personal privacy exposure of the employees and contractors who keep these systems running.

Infostealer logs typically capture far more than corporate login credentials. They can include personal email passwords, banking session cookies, and browsing history tied to an individual's home computer, especially when employees use personal devices for remote access or blend work and personal browsing on the same machine. When that data ends up in a criminal marketplace, it isn't just the utility's network at risk. The employee's personal identity, finances, and other online accounts become exposed too.

This is where infostealer exposure differs from a typical data breach. A breach usually involves a single company's systems being compromised directly. Infostealer infections, by contrast, often originate on an individual's device, sometimes entirely unrelated to their employer's network security. Yet once credentials are stolen, they can be reused to pivot into corporate systems, vendor portals, or third-party software used across the water sector. That dynamic helps explain why SpyCloud frames this as a supply chain issue: a single infected laptop belonging to a contractor or vendor employee can create a foothold that ripples across multiple utilities.

A Sector Already Under Scrutiny

Water utilities have faced mounting cybersecurity attention in recent years, from federal warnings about exposed industrial control equipment to inspector general assessments flagging high-risk deficiencies at drinking water systems nationwide. Infostealer malware surged broadly in 2024, with security researchers tracking tens of millions of infected hosts and billions of stolen credentials circulating across criminal forums. Water utilities, many of which are small municipal operations with limited IT staff and budgets, are not immune to that broader trend.

What makes the water sector particularly sensitive is the combination of critical infrastructure status and resource constraints. Large utilities may have dedicated security teams monitoring for credential leaks, but thousands of smaller systems serving individual towns and counties often lack that capacity entirely. SpyCloud's report suggests that infostealer exposure isn't concentrated among a few large targets, but spread across a large swath of the roughly tens of thousands of water systems the EPA oversees, many of which rely on shared vendors and contractors that could serve as a common point of failure.

What This Means For You

If you work for or contract with a water utility, or simply live in a community served by one, this report is a reminder that infrastructure security increasingly depends on individual digital hygiene, not just institutional IT policy. Infostealer malware typically spreads through phishing emails, malicious ads, cracked software, and fake browser updates, meaning any employee's personal device can become an entry point into a critical system.

For the general public, the direct risk is limited: this report does not indicate that any water supply has been tampered with. But it underscores how interconnected privacy and infrastructure security have become. Credential theft aimed at an individual can eventually affect public services relied upon by entire communities.

Practical Steps Forward

Utilities and their vendors can reduce this risk by monitoring for exposed credentials tied to their domains, enforcing multi-factor authentication so a stolen password alone isn't enough to gain access, and separating personal and work device use wherever possible. Individuals working in or around critical infrastructure sectors should treat password reuse and unmanaged personal devices as genuine organizational risks, not just personal inconveniences.

The SpyCloud findings won't be the last word on infostealer exposure in critical infrastructure. As malware-as-a-service operations continue to scale, expect more sectors, not just water utilities, to face similar scrutiny over credential-based supply chain risk in the months ahead.