While the quantum computing industry is busy announcing post-quantum encryption partnerships for government networks, researchers have found that America's water providers are being compromised by something far less exotic: stolen passwords. No zero-days, no nation-state cryptographic attacks. Just credentials pulled from data breaches and reused on utility control systems. The gap between the security infrastructure we are building for tomorrow and the one we are failing to maintain today is not a technical problem. It is a political economy problem.

Post-Quantum Security Versus Forgotten Password Hygiene

This week alone, Quantum XChange and Carahsoft announced a post-quantum cryptography partnership aimed at government networks, and Aviatrix launched "Harvest and Decrypt Protection" to guard against future quantum-enabled attacks. These are real and necessary preparations: a sufficiently powerful quantum computer could theoretically break today's encryption by performing calculations that no classical machine could complete in useful time. But the water providers getting hacked right now are not being undone by quantum adversaries. They are being undone by the same credential-stuffing attacks that have plagued consumer apps for a decade.

The Infrastructure Attention Gap

The asymmetry is telling. Capital and press attention flow toward the sophisticated future threat while the mundane present threat persists unaddressed. A 2026 arXiv paper on data center environmental accountability makes an adjacent point about infrastructure metrics: the numbers we measure are not always the numbers that matter most. PUE scores and quantum fidelity rates are legible and marketable. "We changed our passwords" is not a press release. Critical infrastructure security is an attention economy failure as much as a technical one, and the chronically online world that tracks every AI benchmark update has not yet found a way to make password hygiene trend.