U.S. Water Systems Are Already Under Cyberattacks. Now A Key Technology Supplier Has Been Hacked Too.
The FBI is investigating the breach at Kansas-based Micro-Comm after a ransomware group published nearly 850,000 files allegedly stolen from the company.

The FBI is investigating a cyberattack on Kansas-based Micro-Comm, a maker of technology used by U.S. water and wastewater facilities, after a ransomware group claimed to have stolen and published nearly 850,000 company files containing about 644 gigabytes of data.
Micro-Comm discovered the breach on July 31, co-owner Jim Cote told Reuters. The company said the attack was limited and did not expose customer passwords, credentials or information allowing Micro-Comm to remotely access its equipment. Barracuda, a relatively new ransomware group that describes itself as financially motivated rather than government-backed, claimed responsibility and posted the files on Aug. 6.
The breach coincided with a separate surge of attacks against programmable logic controllers, or PLCs, used at water utilities around the country. Since July 27, water and wastewater operators in at least seven states have reported cyber incidents, some of which degraded water operations, according to an FBI public-service announcement. Attackers changed passwords and IP addresses on internet-facing devices, cutting operators off from monitoring and control functions.
Federal authorities have separately warned that Iranian-affiliated hackers are targeting internet-connected operational technology across U.S. critical infrastructure. In July, CISA said activity previously focused on Rockwell Automation equipment had expanded to include devices made by Schneider Electric and Siemens. The government has not linked the Micro-Comm breach to that campaign, and Cote said the FBI told the company its attack appeared opportunistic rather than specifically targeted.
The number of industrial devices exposed online remains a concern for authorities. Internet-monitoring company Censys identified thousands of publicly accessible devices made by Rockwell, Siemens and Schneider Electric after CISA's July warning. Reuters reported that roughly 200 Micro-Comm SCADAview CSX systems operating in U.S. states were also accessible from the internet.
Federal agencies have urged water operators to remove PLCs and other operational technology from direct internet exposure. CISA said some recent attacks had forced utilities into sustained manual operations and led to boil-water notices after hackers altered device passwords and network settings.
The threat has also expanded beyond conventional attack tools. An Aug. 19 U.S. government advisory warned that attackers were using AI-generated scripts against Siemens S7 controllers, which are deployed across water, energy, manufacturing and other industrial systems. Siemens subsequently updated its security guidance, advising customers to follow government recommendations and protect industrial-control equipment from unnecessary internet exposure.
© Copyright IBTimes 2026. All rights reserved.

























