
Most cyberattacks come to you — a phishing email, a scam text. A watering-hole attack flips that around: instead of chasing the target, the attacker poisons a place the target already trusts and waits. It is patient, clever, and aimed at groups rather than individuals. Our GetMyPassword team explains what a watering-hole attack is and how to stay safe from one.

What a watering-hole attack is
The name comes from nature: a predator does not chase every animal — it waits by the watering hole where they all come to drink. In cyber terms, attackers compromise a legitimate website that a specific group regularly visits — an industry forum, a supplier’s site, a niche community — and use it to infect those visitors. You are caught not because you were targeted directly, but because you trusted the wrong watering hole.
How it works
- Pick the prey: attackers choose a target group, such as a company’s staff.
- Poison the water: they hack a trusted site that group visits often.
- Wait: when victims visit, hidden code tries to drop malware or steal logins.
- Move in: a single infected device becomes a foothold into the real target.
Why it is dangerous
Watering-hole attacks are hard to spot because the site is genuinely one you trust — there is no suspicious email to ignore. They often exploit unpatched vulnerabilities in your browser or plugins, so an out-of-date device is the real weak point. Because they target groups, they are a favorite tool for attacks on companies and organizations.
You cannot always tell a poisoned watering hole by looking — the site is real. What you can control is being a hard target: an updated device, security software, and logins that survive even if a password is stolen.
How to protect yourself
You cannot vet every site, so harden the device instead. Keep your browser and system updated, since these attacks rely on old vulnerabilities; run reputable security software; and never dismiss browser security warnings. Crucially, make stolen credentials useless: give every account a unique password from our password generator and turn on two-factor authentication, so a login grabbed at a watering hole opens nothing.
Frequently asked questions
What is a watering-hole attack in simple terms?
It is an attack where criminals compromise a legitimate website a target group often visits, then infect those visitors. Rather than targeting you directly, they poison a site you already trust and wait for you to come.
How is a watering-hole attack different from phishing?
Phishing lures you with a fake message you must act on. A watering-hole attack waits on a real, trusted website you visit anyway, with no email needed, which makes it harder to notice.
How can I protect myself from watering-hole attacks?
Keep your browser and system updated, use reputable security software, and heed browser warnings. Use unique passwords and two-factor authentication so any credentials stolen at a compromised site cannot be reused.



