< Back to all clusters
[TECHNOLOGY] · United States · 3 sources

started · updated

Micro-Comm water technology supplier targeted in FBI-investigated cyberattack

The FBI is investigating a cyberattack on Micro-Comm, a Kansas-based manufacturer of programmable logic controllers (PLCs) used in wastewater facilities. The breach, which Micro-Comm discovered on July 31, involves the theft of approximately 850,000 files totaling 644 GB of data. The Barracuda ransomware group has claimed responsibility, stating their motivations are profit-driven rather than state-sponsored.

Stolen data reportedly includes product diagrams, employee information, and references to specific government customers, including a U.S. military facility. While the breach highlights vulnerabilities in the supply chain for critical water infrastructure, Micro-Comm stated that passwords, customer credentials, and remote access information were not exposed. The company also noted there is no evidence that the breach led to the operational compromise of any water systems.

The FBI indicated that this specific incident appears to be an opportunistic attack and is likely separate from a recent wave of cyberattacks targeting water utilities in at least seven states, which experts believe are linked to an Iranian-affiliated campaign. This broader campaign has targeted PLCs from major manufacturers including Rockwell Automation, Schneider Electric, and Siemens. CISA has also warned that threat actors are increasingly using AI to facilitate attacks on industrial equipment.

Entities

Barracuda · CISA · FBI · Micro-Comm · Siemens

Claims

What the coverage asserts, and how many sources carry each claim.