FBI Probes Breach at Water-Tech Supplier as Critical Infrastructure Threats Mount
FBI investigates ransomware breach at Kansas water-tech firm Micro-Comm; officials say attack was opportunistic, not linked to Iran campaign.
U.S. authorities are investigating a ransomware attack on Micro-Comm, a small Kansas-based maker of technology used by water utilities, in a case that underscores persistent cybersecurity vulnerabilities in the nation's critical infrastructure.
The FBI confirmed it is in contact with the company, which discovered the breach on July 31. The attack was claimed by Barracuda, a profit-driven ransomware group that says it is not government-sponsored. On August 6, the group posted what it said were nearly 850,000 company files, totaling roughly 644 gigabytes of data.
Micro-Comm, based in Olathe, Kansas, manufactures programmable logic controllers (PLCs) — computer devices that control machinery in critical infrastructure networks, including wastewater processing facilities. The company said the released files did not contain sensitive information such as user passwords or credentials, which are stored by customers, nor data related to remote access to its devices.
The breach came amid a late-July spate of attacks targeting PLCs in Minnesota and at least six other states. Cybersecurity experts believe those attacks were part of a long-running Iranian-affiliated campaign. The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) warned on July 30 that hackers were targeting PLCs from Rockwell Automation, Schneider Electric, and Siemens. CISA said on August 19 that hackers were using AI to ease attacks on Siemens equipment; the company said it was working with CISA and that its products are safe.
Jim Cote, a co-owner of Micro-Comm, said the FBI told the company the breach was an opportunistic attack, not specifically targeted at the firm. The company advised customers to change passwords out of caution. Roughly 200 of its SCADAview CSX systems in use across U.S. states are accessible from the internet, according to monitoring firm Censys.
A list of files gathered by cybercrime research platform eCrime.ch references specific government customers, including localities and a U.S. military facility, along with employee names and product diagrams. Tom Hegel, a senior threat researcher at SentinelOne, said the file release did not mean any water system was operationally compromised, but the information could aid hackers in the long term.