FBI Probes Hack of Water Tech Supplier Amid Iran-Linked Cyber Campaign
Federal investigators are probing a data breach at Micro-Comm, a Kansas maker of water utility equipment, after a ransomware group posted hundreds of thousands of company files — an attack authorities described as opportunistic and separate from a suspected Iranian campaign that hit water plants in multiple states starting in July.
The FBI is investigating a data breach at Micro-Comm, a small Kansas manufacturer of programmable logic controllers used in wastewater treatment facilities, after a ransomware group claimed responsibility and posted nearly 850,000 company files online. The breach, which the company discovered on July 31, comes amid a spate of cyberattacks targeting water infrastructure across the United States that cybersecurity experts believe are linked to Iranian-affiliated actors.
Micro-Comm, based in Olathe, Kansas, confirmed the attack, which has not previously been reported. The company and the FBI said the incident was not part of the suspected Iranian campaign that beginning in late July targeted programmable logic controllers (PLCs) in Minnesota and at least six other states. Instead, FBI officials told the company the breach was an “opportunistic attack” not specifically aimed at Micro-Comm.
The ransomware group Barracuda, a relatively new actor that claims to be profit-motivated and not government-sponsored, posted on August 6 what it said was approximately 850,000 company files totaling roughly 644 gigabytes of data. Micro-Comm makes PLCs — computer devices used to control machinery within critical infrastructure networks, in this case for wastewater processing facilities.
Jim Cote, a co-owner of Micro-Comm, said the company discovered the breach on July 31. He said the files released by the hackers did not contain sensitive information such as user passwords and credentials, which are stored by customers, nor data related to Micro-Comm’s ability to remotely access its devices. In an August 8 newsletter to customers, the company said it experienced a “limited malware attack” and that any sensitive information in the files was encrypted. The company stated the breach was “in no way related to water system hacks currently being reported on the news.”
Cote said the FBI advised the company that the data breach was opportunistic, and Micro-Comm recommended customers change passwords out of an abundance of caution.
Dixon Land, a spokesperson for the FBI’s Kansas City field office, said in an email that the FBI was in contact with Micro-Comm about the hack and coordinating with other law enforcement agencies. The Cybersecurity and Infrastructure Security Agency (CISA) referred questions to Micro-Comm.
Despite the company’s assurances, security researchers noted potential long-term risks. Tom Hegel, a senior threat researcher at cybersecurity firm SentinelOne, said the release of files did not mean any water system was operationally compromised, but the information could help hackers in the long term.
A list of files gathered by cybercrime research platform eCrime.ch refers to specific government customers, including localities and a U.S. military facility, employee names, and product information such as diagrams. According to internet-monitoring firm Censys, roughly 200 of Micro-Comm’s SCADAview CSX systems — one of the company’s products — that are in use in U.S. states are accessible from the internet.
The Micro-Comm breach highlights the complexity of securing local U.S. water systems and the vendors that support them from increasing cyberattacks on computer systems embedded in the nation’s critical infrastructure.
The incident occurred during a broader cybersecurity crisis for water utilities. In late July, hackers targeted PLCs in Minnesota and at least six other states. The FBI and CISA warned on July 30 that hackers were targeting PLCs from U.S.-based Rockwell Automation, France’s Schneider Electric, and Germany’s Siemens. On August 19, CISA said hackers were using AI to ease their attacks on Siemens equipment. Siemens subsequently said it was working with CISA and that its products are safe.
Cybersecurity experts believe those attacks were part of a long-running Iranian-affiliated cyber campaign. While the Micro-Comm breach was not linked to that campaign, the simultaneous incidents underscore the vulnerability of critical water infrastructure to both targeted state-backed operations and opportunistic ransomware attacks.
The market implications are clear: major industrial automation firms — Rockwell Automation (ROK.N), Schneider Electric (SCHN.PA), and Siemens (SIEGn.DE) — have seen their equipment targeted, raising concerns about supply chain risk and the cybersecurity posture of the broader water sector. The breach at a small vendor like Micro-Comm demonstrates that even niche suppliers with internet-accessible systems can become vectors for data theft, potentially affecting government and military customers.
The investigation by the FBI’s Kansas City field office is ongoing.
相关文章
您可能还喜欢




