Key Takeaways

  • Barracuda claimed it published nearly 850,000 Micro-Comm files totaling roughly 644 gigabytes after a July 31 breach.
  • Micro-Comm said customer credentials and remote-access data were not exposed, and no operational compromise of water systems has been reported.
  • The incident puts a spotlight on supplier security as attackers increasingly target internet-accessible industrial control systems.

The FBI is investigating a cyberattack on Micro-Comm, an Olathe, Kansas, manufacturer whose control technology is used by wastewater facilities and other public infrastructure operators.

Micro-Comm discovered the breach on July 31, according to a company co-owner. Barracuda, a relatively new ransomware group that describes itself as financially motivated rather than government sponsored, claimed responsibility. On Aug. 6, Barracuda posted what it said were nearly 850,000 Micro-Comm files representing roughly 644 gigabytes of data.

The timing was striking. The Micro-Comm incident surfaced during a late July 2026 wave of attacks against programmable logic controllers, or PLCs, in Minnesota and at least six other states. Cybersecurity specialists have associated that broader activity with a long-running Iranian-affiliated campaign.

Micro-Comm, however, said its breach was separate. In an Aug. 8 customer newsletter, Micro-Comm described the event as a limited malware attack and said sensitive material within the affected files was encrypted. Micro-Comm also said the breach was in no way related to water system hacks currently being reported on the news.

A spokesperson for the FBI's Kansas City field office confirmed that the bureau was in contact with Micro-Comm and coordinating with other law enforcement agencies. The company co-owner said the FBI characterized the breach as opportunistic rather than an operation that specifically selected Micro-Comm.

That distinction matters for attribution, but it does not erase the wider business risk. A financially motivated ransomware operator and a state-affiliated group can enter different systems for different reasons while still exposing the same structural weakness: poorly protected technology suppliers and internet-facing industrial equipment.

Compromising a water utility's vendor does not automatically give attackers control over pumps, treatment processes or chemical systems. Still, stolen employee information, customer references and technical diagrams can support reconnaissance for later attacks.

A list of the files attributed to Barracuda referred to government customers, including localities and a US military facility. It also included employee names and product information such as diagrams. The presence of those records does not establish that any customer environment was penetrated or that a water system was operationally affected.

Micro-Comm said the released material did not include customer passwords or credentials, which customers store themselves. The co-owner also said it did not contain information connected to Micro-Comm's ability to access its equipment remotely. Even so, Micro-Comm advised customers to change passwords as a precaution.

Exposure remains a practical concern. Roughly 200 SCADAview CSX systems operating in US states are accessible through the internet, according to internet-monitoring firm Censys. Internet accessibility is not proof of vulnerability, but it creates a discoverable attack surface. Restricting remote exposure minimizes the chance of giving an opportunistic intruder a visible doorway.

On July 30, the FBI and Cybersecurity and Infrastructure Security Agency warned that attackers were targeting PLCs made by Rockwell Automation, Schneider Electric and Siemens. CISA said on Aug. 19 that attackers were using AI to make attacks on Siemens equipment easier. Siemens subsequently said it was working with CISA and that its products were safe.

Earlier government guidance documented how IRGC-affiliated actors, often identified as CyberAv3ngers, exploited internet-connected water and wastewater PLCs through exposed ports and default credentials. Recent attacks have reportedly included password changes, boil-water notices and extended periods of manual operation.

For utility executives, the response goes beyond patching one device. NIST Cybersecurity Framework 2.0 offers a governance structure for identifying supplier exposure, assigning responsibility and planning recovery. The ISA/IEC 62443 series provides more industrially focused guidance covering system segmentation, access controls and secure product development.

That said, smaller utilities and their suppliers often operate with limited staffing and long equipment lifecycles. Progress may come from basic measures applied consistently: removing unnecessary internet exposure, replacing default credentials, separating operational technology from business networks, testing manual procedures and requiring vendors to disclose incidents quickly. The Micro-Comm breach shows why supplier files deserve protection even when the machinery itself keeps running.