FBI Investigates Ransomware Breach at Water-Sector Control-System Maker Micro-Comm

The FBI is investigating a ransomware attack and data theft at Micro-Comm, a Kansas-based manufacturer of programmable logic controllers used across US water and wastewater utilities, according to an exclusive Reuters report published August 26, 2026, and corroborated by BrinzTech and IBTimes.

Micro-Comm, based in Olathe, discovered the breach on July 31, 2026. A relatively new ransomware group calling itself Barracuda claimed responsibility on August 6, posting what it said was roughly 850,000 company files totaling about 644 gigabytes of data. Dixon Land, a spokesperson for the FBI’s Kansas City field office, confirmed the bureau is in contact with Micro-Comm and coordinating with other law enforcement agencies.

Attack Described as Opportunistic, Not Targeted

Micro-Comm told Reuters the FBI characterized the intrusion as an opportunistic attack rather than one specifically aimed at the company, and that the leaked files did not include customer credentials or data related to the company’s ability to remotely access its devices. Roughly 200 of Micro-Comm’s SCADAview CSX systems — used to monitor and control equipment at customer sites — are reachable from the public internet, a configuration security researchers have flagged as a broader risk across the water sector.

The disclosure comes amid heightened federal scrutiny of Iran-linked cyber activity against water infrastructure, following a wave of intrusions this summer affecting wastewater treatment plants across a dozen US states, though officials say the Micro-Comm incident and the earlier nation-state activity are being tracked as separate matters.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *