America's water treatment systems purify billions of gallons of drinking water every day. Researchers now warn that a familiar, preventable failure — stolen or weak passwords — is leaving those systems dangerously exposed to the kinds of cyberattacks that could contaminate supplies, disrupt service, or worse.
Security researchers have identified credential theft as a mounting threat to some of the country's most critical infrastructure. The finding lands against a backdrop of rising attacks on operational technology environments, federal warnings from the Cybersecurity and Infrastructure Security Agency, and a water sector that has historically lagged far behind other industries in basic digital hygiene.
Why Stolen Passwords Threaten America's Water Infrastructure
Water utility cybersecurity occupies an unusual position in the broader landscape of critical infrastructure protection. Unlike financial institutions or major technology companies, most water providers are small municipal operations staffed by civil engineers and plant operators — not security professionals. Many systems rely on operational technology, commonly called OT, that predates modern authentication standards by decades.
OT environments were originally designed to be isolated from the internet entirely. That isolation has steadily eroded. Remote monitoring, cloud-connected sensors, and internet-facing administrative portals have become standard across the sector. A password protecting a remote access portal to a water treatment system is no longer a minor administrative detail. It is, often, the single barrier standing between the public drinking water supply and an adversary sitting anywhere in the world.
When that password is stolen — harvested through phishing, purchased from a dark web credential market, or extracted from a breach at a third-party vendor — the consequences are not theoretical.
The Scale of the Problem: What Researchers Found
Security researchers have flagged credential exposure as one of the most acute risks facing water utilities today. Their concern reflects a broader pattern documented across industries. The Verizon Data Breach Investigations Report has consistently found that stolen or weak credentials are involved in over 80 percent of hacking-related breaches, year after year. There is little reason to believe the water sector is immune — and considerable evidence suggesting it is more vulnerable than most.
Read next Laika's Wildwood: Stop-Motion Fantasy at TIFF 2026Water systems across the United States range from massive metropolitan authorities serving millions of residents to tiny rural operators maintaining a few dozen connections. The American Water Works Association estimates there are approximately 148,000 public water systems in the country. The vast majority operate on tight budgets, with no dedicated cybersecurity staff and minimal investment in security tooling.
For researchers, that combination — high-value targets, weak authentication practices, and under-resourced operators — creates a systemic vulnerability that bad actors are increasingly positioned to exploit.
How Hackers Exploit Water Utility Credentials
The attack pathway is not sophisticated. An adversary obtains valid credentials, often through automated scanning of credential databases assembled from prior corporate breaches. They test those credentials against internet-exposed remote access tools, virtual private network portals, or industrial control system interfaces. If an operator has reused a password from a compromised personal account, or if a utility never changed a vendor-supplied default password, the door opens.
Once inside, the intrusion often goes undetected for extended periods. OT environments rarely carry the same logging, monitoring, and anomaly detection capabilities common in enterprise IT networks. An attacker with access to a supervisory control and data acquisition system — what the industry calls SCADA — can observe operations, learn system behavior, and position themselves to manipulate physical processes such as chemical dosing or pump controls.
The threat is compounded by the interconnected nature of modern water infrastructure. A single compromised credential may provide access not just to one facility but to a broader network of sites managed under the same administrative platform. Vendors that service multiple utilities can inadvertently serve as force multipliers for an attacker who compromises shared credentials.
Past Attacks on Water Systems: A Pattern of Vulnerability
The danger is not hypothetical. In February 2021, an attacker remotely accessed the water treatment plant in Oldsmar, Florida and briefly changed the sodium hydroxide concentration to a potentially dangerous level — 111 times the normal amount. An alert operator noticed the change and reversed it before any contaminated water reached residents. The attacker had used remote desktop software that was improperly secured. The town's operator had seen the cursor move across the screen and taken manual control.
That incident became a flashpoint for federal regulators. CISA, the Environmental Protection Agency, and the FBI issued a joint advisory warning water utilities about the risks posed by inadequate remote access controls, legacy systems, and weak password practices. The advisory specifically flagged the use of end-of-life operating systems and the failure to use multi-factor authentication as critical vulnerabilities.
The EPA has since issued cybersecurity guidance urging water utilities to conduct risk assessments, implement access controls, and train staff to recognize social engineering attacks. CISA's cross-sector advisories on industrial control system security consistently list credential management as a foundational control. Despite those warnings, adoption across the water sector has remained uneven, particularly among smaller systems that lack the resources to act on guidance even when they are aware of it.
What Water Utilities Must Do to Protect Themselves
Water utility cybersecurity improvement does not require exotic technology. The most effective interventions are also the most basic, and the evidence base behind them is solid.
Multi-factor authentication is the single highest-impact control any utility can deploy. Stolen passwords become largely useless when an attacker also needs a second factor — a hardware token, an authenticator application, or a biometric confirmation — to complete a login. CISA has designated MFA as a critical security practice for all organizations operating industrial control systems.
Credential hygiene extends beyond MFA. Utilities should enforce unique, complex passwords for all accounts with access to operational systems. Default vendor credentials — frequently unchanged across thousands of installations — must be rotated immediately upon deployment. Privileged access should be scoped narrowly, following the principle of least privilege, so that a compromised account for routine monitoring cannot also control chemical dosing.
Network segmentation reduces the blast radius of any successful intrusion. Keeping OT environments logically and physically separated from IT systems and internet-facing infrastructure makes lateral movement harder. Monitoring and alerting on anomalous login behavior — failed attempts, access from unusual locations, logins outside normal operating hours — can surface intrusions before they escalate.
Staff training remains underinvested across the sector. Phishing and social engineering are the most common initial access vectors for credential theft. Regular, realistic training exercises are among the most cost-effective defenses available.
The Broader Implications for Critical Infrastructure Security
Researchers raising alarms about water systems are pointing to something larger than any single vulnerability. The water sector's exposure reflects a structural challenge facing critical infrastructure broadly: the gap between the pace of digital integration and the pace of security investment.
Operational technology environments across water, energy, transportation, and manufacturing were built for reliability and longevity, not for an era of persistent adversarial pressure from nation-state actors and criminal ransomware groups. As those environments connect to corporate networks and the internet, the security assumptions embedded in their original designs no longer hold.
The stakes in the water sector are particularly stark because the consequences of a successful attack are immediate and physical. Disrupted chemical treatment or pump operations do not produce an outage notice on a website. They affect the safety of drinking water serving schools, hospitals, and homes.
The researchers' warning should be read as a call to treat water utility cybersecurity as a public health issue, not merely a technology problem. Credential theft is not a sophisticated or novel threat. It is a known, documented, and largely solvable one. The fact that it remains a leading threat vector across critical infrastructure — years after the Oldsmar incident, after repeated federal advisories, after sustained research attention — is a policy failure as much as a technical one.
Federal funding under the Infrastructure Investment and Jobs Act included provisions for water system upgrades, including some cybersecurity-related investments. Whether that funding reaches the smallest, most exposed operators — and whether it translates into the unglamorous but essential work of locking down remote access portals and enforcing strong authentication — will determine how the next chapter of this story reads.
Source: TechCrunch



