FBI investigates cyberattack targeting Micro-Comm, a major U.S. manufacturer of specialized industrial control hardware used in municipal water and wastewater system (WWS) facilities.
The breach—confirmed by both the Kansas-based supplier and the Federal Bureau of Investigation (FBI)—comes as federal security officials manage a nationwide surge of intrusions hitting public water systems across multiple states.
Inside the Intrusion: SCADA Diagrams and Corporate Files Could Exposed
The attack was claimed by Barracuda, a ransomware group. On August 6, the group published approximately 644 gigabytes of data—comprising roughly 850,000 corporate files—stolen from Micro-Comm’s internal networks.
Dixon Land, a spokesperson for the FBI’s Kansas City field office, told Reuters, that the FBI was in contact with Micro-Comm about the hack and coordinating with other law enforcement agencies. CISA referred questions to Micro-Comm.
Jim Cote, a co-owner of the Micro-comm company, said in an interview that the company discovered the breach on July 31. Cote said
the files released by the hackers did not contain sensitive information such as user passwords and credentials, which are stored by the customer, or data related to Micro-Comm’s ability to remotely access its devices.
- What Was Compromised: Leaked documents included confidential data reports.
- The Supply Chain Risk: Micro-Comm develops Programmable Logic Controllers (PLCs) and Supervisory Control and Data Acquisition (SCADA) software, such as SCADAview CSX. Cybersecurity researchers at Sentinel One warned that while the leak does not grant immediate control over plants, public exposure of technical blueprints provides malicious actors with a roadmap for future targeted exploits.
- Vendor Response: Micro-Comm stated that sensitive files were encrypted and advised clients to reset system credentials as a precautionary measure.
In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem.
A Broadening Cyber Threat Landscape for American Utilities
The Micro-Comm investigation unfolds alongside a coordinated federal response to intrusions targeting municipal drinking and wastewater facilities across at least 12 U.S. states.
- Industrial Hardware Targeted: The FBI, CISA and NSA warn that threat actors, including Iran-linked groups, are targeting exposed PLCs from Siemens, Rockwell Automation and Schneider Electric.
- AI-Assisted Attacks: The Cyber threat actors are using AI-powered tools and automation to find vulnerable industrial systems and develop targeted payloads immidiately.
- Water Utilities Targeted: Municipal facilities in Minnesota, Michigan, New Jersey, Georgia and South Dakota have reported attempts to interfere with OT systems.
- Quick Response Prevented Damage: In some cases, engineers switched systems to manual controls, helping prevent serious operational disruptions.
This week we reported, Iran-Linked Hackers Cyberattack On UK Power Plant, Offline for Four Days
Required Security Mandates for Water Utilities
The EPA, FBI, and CISA have renewed calls for critical infrastructure operators to audit their supply chains and enforce strict network isolation.
- Disconnect Exposed Controllers from the Internet: PLCs and SCADA systems connected through unsecured cellular modems or direct internet connections should be taken offline immediately.
- Review Third-Party Access: Water utilities should audit remote-access permissions given to vendors, system integrators, and managed service providers, and remove any access that is no longer required.
- Use Physical PLC Controls: Where supported, keep PLC key switches in “RUN” mode instead of “REMOTE” to help prevent unauthorized changes to control logic through network connections.