Key facts
- Micro-Comm, a supplier of technology for water utilities, suffered a data breach.
- The FBI is investigating the incident.
- The attack occurred during a period of increased cyber threats against U.S. water systems.
- Hackers claimed responsibility and released company files.
- The company stated sensitive information was encrypted and not compromised.
U.S. authorities are investigating a data breach at Micro-Comm, a small maker of water utility technology based in Olathe, Kansas. The attack, claimed by a ransomware group known as Barracuda, has drawn scrutiny from the FBI, highlighting the vulnerability of critical infrastructure to cyber threats. Barracuda claimed to have released nearly 850,000 company files, totaling approximately 644 gigabytes of data, on August 6.
Micro-Comm produces programmable logic controllers (PLCs), essential devices for controlling machinery in critical infrastructure, including wastewater processing facilities. The breach underscores the challenges in securing local U.S. water systems and their supporting vendors against escalating cyberattacks.
This incident occurred during a period of increased cyber activity targeting PLCs in Minnesota and at least six other states. Cybersecurity experts suspect these attacks are part of a sustained campaign linked to Iran. The FBI and CISA had previously warned on July 30 about hackers targeting PLCs from major manufacturers like Rockwell Automation, Schneider Electric, and Siemens. CISA also noted on August 19 that hackers were leveraging AI to facilitate attacks on Siemens equipment.
Dixon Land, an FBI spokesperson, confirmed the agency's engagement with Micro-Comm and coordination with other law enforcement bodies. Jim Cote, a co-owner of Micro-Comm, stated the company discovered the breach on July 31. He emphasized that the released files did not contain sensitive user passwords, credentials, or data related to the company's remote access capabilities, and that any sensitive information within the files was encrypted. Micro-Comm informed customers on August 8 that the attack was limited and unrelated to other ongoing water system hacks.
Cote also relayed that the FBI characterized the breach as an opportunistic attack, not specifically targeting Micro-Comm. The company advised customers to change passwords as a precautionary measure. Internet monitoring firm Censys indicated that approximately 200 of Micro-Comm's SCADAview CSX systems are accessible via the internet. A list of files compiled by cybercrime research platform Cybernews referenced specific government customers, including local governments and a U.S. military facility, along with employee names and product details. Tom Hegel, a threat researcher at SentinelOne, noted that while the file release might not immediately compromise water systems, the information could aid hackers in the future.
