Category: Water

  • FBI Investigates Ransomware Breach at Water-Sector Control-System Maker Micro-Comm

    FBI Investigates Ransomware Breach at Water-Sector Control-System Maker Micro-Comm

    The FBI is investigating a ransomware attack and data theft at Micro-Comm, a Kansas-based manufacturer of programmable logic controllers used across US water and wastewater utilities, according to an exclusive Reuters report published August 26, 2026, and corroborated by BrinzTech and IBTimes.

    Micro-Comm, based in Olathe, discovered the breach on July 31, 2026. A relatively new ransomware group calling itself Barracuda claimed responsibility on August 6, posting what it said was roughly 850,000 company files totaling about 644 gigabytes of data. Dixon Land, a spokesperson for the FBI’s Kansas City field office, confirmed the bureau is in contact with Micro-Comm and coordinating with other law enforcement agencies.

    Attack Described as Opportunistic, Not Targeted

    Micro-Comm told Reuters the FBI characterized the intrusion as an opportunistic attack rather than one specifically aimed at the company, and that the leaked files did not include customer credentials or data related to the company’s ability to remotely access its devices. Roughly 200 of Micro-Comm’s SCADAview CSX systems — used to monitor and control equipment at customer sites — are reachable from the public internet, a configuration security researchers have flagged as a broader risk across the water sector.

    The disclosure comes amid heightened federal scrutiny of Iran-linked cyber activity against water infrastructure, following a wave of intrusions this summer affecting wastewater treatment plants across a dozen US states, though officials say the Micro-Comm incident and the earlier nation-state activity are being tracked as separate matters.

  • Iran-Linked Hackers Disable UK Power Plant for Four Days as US Water Utilities Report Coordinated Attacks

    Iran-Linked Hackers Disable UK Power Plant for Four Days as US Water Utilities Report Coordinated Attacks

    A small power generation facility in the United Kingdom was disabled for four days after a suspected Iran-linked cyberattack, in a window that overlapped with a wider wave of intrusions against wastewater treatment plants across roughly a dozen US states, according to reporting from Security Affairs and The Register published August 23–24, 2026, citing UK government and industry sources.

    The UK facility, not named publicly for security reasons, was small enough that its outage did not affect the wider national power supply, and staff were able to restore operations without formal notification thresholds being triggered. A UK government source told reporters the plant fell below the legal reporting threshold for “important generators,” while the National Cyber Security Centre declined to comment on the specific incident. NCSC chief Richard Horne said in June that the agency had handled more than 200 attacks on UK critical national infrastructure over the preceding year.

    US Wastewater Plants Hit Across Multiple States

    In parallel, US authorities traced a separate series of intrusions affecting dozens of wastewater treatment facilities, with the earliest reports emerging from Minnesota on July 26 and subsequent incidents confirmed in Michigan, Georgia, South Dakota, New Jersey, and Alabama. Several affected utilities reported flooding and loss of water pressure, and some jurisdictions issued boil-water advisories as a precaution. The FBI has attributed the water-sector intrusions to “malicious cyber actors,” and US government sources cited by Security Affairs indicated the activity likely originated in Iran.

    Researchers characterize both incidents as capability demonstrations rather than attempts to cause lasting damage, consistent with a broader pattern of suspected Iranian probing reported in recent months against infrastructure operators in Germany, Poland, Finland, Belgium, and Albania. UK officials have said the activity has accelerated since February airstrikes involving the United States and Israel against Iranian targets.

    The incidents add to a year in which operational technology at water and wastewater facilities has faced sustained scrutiny, and follow a separate US executive action restricting foreign-made equipment in bulk-power systems over cybersecurity concerns.

  • Water and Wastewater Treatment Facility Security Technology

    Water and Wastewater Treatment Facility Security Technology

    Water and wastewater treatment facilities occupy an unusual position among critical infrastructure sectors: they are simultaneously among the most physically distributed — with treatment plants, pump stations, storage tanks and distribution infrastructure often spread across large geographic areas — and among the most operationally sensitive, since a disruption can affect public health directly rather than only causing economic damage. U.S. federal agencies, including CISA, have repeatedly flagged the sector for elevated attention, warning water and wastewater system operators to protect programmable logic controllers (PLCs) and other operational-technology assets against reconnaissance and exploitation attempts by both criminal and state-linked threat actors.

    Physical Security Layers

    Perimeter Protection at Distributed Sites

    Because water infrastructure includes remote, often unstaffed sites such as pump stations and lift stations, perimeter security technology for the sector leans heavily on remote-monitoring approaches: fence-mounted or buried intrusion sensors, thermal and visible-light cameras with video analytics tuned for rural or low-activity environments, and cellular or satellite backhaul for sites without reliable wired connectivity. Given the number of remote sites a typical utility must cover, cost-effective, low-maintenance sensing technology is often prioritized over higher-precision but more expensive systems better suited to single high-value facilities.

    Access Control for Critical Process Areas

    Within treatment plants, access control is typically layered around process criticality: chemical storage and dosing areas, SCADA control rooms, and treatment process areas warrant stricter access restrictions than administrative buildings. Credential-based access control integrated with visitor management is standard practice for controlling contractor and vendor access, which represents a recurring risk category across critical infrastructure sectors generally.

    Video Surveillance and Analytics

    Video coverage of treatment processes, chemical handling areas and perimeter zones supports both security monitoring and operational documentation. Analytics capable of detecting loitering, unauthorized vehicle presence, or intrusion at remote unstaffed sites help utilities extend effective monitoring coverage without proportionally increasing staffing.

    The Cyber-Physical Dimension

    Water and wastewater utilities have drawn specific attention from cybersecurity agencies because their operational technology — the PLCs and SCADA systems that control chemical dosing, pumping and treatment processes — is frequently older, harder to patch, and in some cases directly internet-accessible due to historical remote-access configurations designed for operational convenience rather than security. Advisories describing reconnaissance and exploitation attempts against water-sector PLCs have specifically warned operators to review remote-access configurations, apply available patches, and segment OT networks from IT infrastructure. This makes the sector a clear example of where physical security and OT cybersecurity cannot be treated as separate disciplines: a compromised remote-access pathway into a chemical dosing PLC is as much a physical-safety issue as a cybersecurity one.

    Practical Constraints Facing the Sector

    Unlike well-funded critical-infrastructure operators in sectors such as energy or aviation, many water and wastewater utilities are small municipal operations with limited security budgets and technical staff. This constraint shapes technology adoption in the sector: solutions that require minimal specialized staffing to operate, that consolidate physical and cyber monitoring into fewer platforms, and that can be deployed incrementally across a large number of small remote sites tend to see faster adoption than more sophisticated but resource-intensive alternatives designed for larger, better-funded facilities.

    FAQ

    Why are water utilities considered attractive targets?

    Water systems combine public-health impact, historically under-resourced cybersecurity programs, and operational technology that in many cases predates modern security design practices — a combination that has drawn attention from both criminal ransomware actors and state-linked groups conducting reconnaissance against OT infrastructure, according to public advisories from CISA and allied agencies.

    What is the biggest practical barrier to improving water-sector security?

    Funding and staffing constraints are widely cited as the primary barrier, particularly for small municipal utilities that lack dedicated cybersecurity or physical-security personnel and must prioritize a limited budget across a large number of distributed sites.

    Conclusion

    Securing water and wastewater infrastructure requires treating physical security, remote-site monitoring and OT cybersecurity as a single integrated problem rather than three separate budget lines. Given the sector’s resource constraints, the technologies most likely to see real-world adoption are those that consolidate monitoring, minimize specialized staffing requirements, and scale cost-effectively across large numbers of distributed, often unstaffed sites.

  • DEF CON Franklin and National Rural Water Association Launch Water Watch Center for Small Utilities

    DEF CON Franklin and National Rural Water Association Launch Water Watch Center for Small Utilities

    DEF CON Franklin and the National Rural Water Association (NRWA) have launched the Water Watch Center, a program giving small water utilities direct access to cybersecurity support, the organizations announced at DEF CON 34 in Las Vegas.

    What’s New

    The Water Watch Center connects small water systems — those serving fewer than 10,000 people, which make up roughly 91% of the nation’s approximately 50,000 community water systems — with five managed detection and response providers: Defendify, Legato Security, L1 Secure, Rapid7 and Sentinel Technologies. The providers exchange threat information and patches through a shared collaboration mechanism and report findings to NRWA, which coordinates response for member utilities. DEF CON Franklin, a partnership between NRWA, the University of Chicago’s Cyber Policy Initiative and DEF CON, also offers a volunteer cyber task force that matches water systems with technologists who help harden OT and IT infrastructure.

    Why It Matters

    “NRWA is excited to establish the Water Watch Center to provide the tools our sector needs to assess, prepare for, and respond to cyberattacks,” said NRWA Chief Executive Officer Matthew Holmes. The launch follows what organizers described as one of the most widespread nation-state cyberattacks on U.S. water systems to date, and comes as small utilities with limited budgets and staff have struggled to access the kind of hands-on cybersecurity support larger utilities can afford.