Micro-Comm, Rockwell Automation, Siemens and Schneider Electric: Hack of Water Sector Supplier Draws FBI Scrutiny as Iran-Linked Cyber Concerns Grow

Micro-Comm, Rockwell Automation, Siemens and Schneider Electric: Hack of Water Sector Supplier Draws FBI Scrutiny as Iran-Linked Cyber Concerns Grow

Cybersecurity Breach at Kansas Water Utility Tech Firm Exposes Critical Infrastructure Risks

US authorities are investigating a data breach at Micro-Comm, a small Kansas-based manufacturer of programmable logic controllers (PLCs) used in wastewater processing facilities. The attack, confirmed by the FBI and the company, was claimed by the ransomware group Barracuda, which posted nearly 850,000 files (644 GB) on August 6, though it denied government affiliation, citing financial motives.

The breach occurred in late July, coinciding with a separate Iranian-linked cyber campaign targeting PLCs in Minnesota and at least six other states. While Micro-Comm’s incident was unrelated to those attacks, it underscored vulnerabilities in local water systems and their supply chains. The FBI and CISA had previously warned on July 30 about hackers targeting PLCs from Rockwell Automation, Schneider Electric, and Siemens, with CISA later reporting on August 19 that attackers were leveraging AI to exploit Siemens equipment.

Micro-Comm, based in Olathe, Kansas, discovered the breach on July 31. Co-owner Jim Cote stated that the leaked files did not contain sensitive credentials or remote access data, as such information is stored by customers. The company notified clients on August 8, assuring them that the malware attack was limited and that encrypted data remained secure. The FBI described the breach as opportunistic, not targeted, and advised customers to update passwords as a precaution.

According to Censys, roughly 200 of Micro-Comm’s SCADAview CSX systems remain exposed online. Leaked files, reviewed by cybercrime researchers, included government customer details, employee names, and product diagrams, potentially aiding future attacks. SentinelOne’s Tom Hegel noted that while no water systems were operationally compromised, the exposed data could be exploited in long-term cyber threats. The incident highlights ongoing risks to critical infrastructure vendors, even those not directly tied to state-sponsored campaigns.

Source: https://www.algemeiner.com/2026/08/26/hack-water-sector-supplier-draws-fbi-scrutiny-iran-linked-cyber-concerns-grow/

Micro-Comm Inc. cybersecurity rating report: https://www.rankiteo.com/company/micro-comm-inc.

Rockwell Automation cybersecurity rating report: https://www.rankiteo.com/company/rockwell-automation

Siemens Industry cybersecurity rating report: https://www.rankiteo.com/company/siemens-industry-

Schneider Electric cybersecurity rating report: https://www.rankiteo.com/company/schneider-electric

"id": "MICROCSIESCH1787761681",
"linkid": "micro-comm-inc., rockwell-automation, siemens-industry-, schneider-electric",
"type": "Ransomware",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Government customers, '
                                              'wastewater processing '
                                              'facilities',
                        'industry': 'Water Utility Technology, Industrial '
                                    'Control Systems',
                        'location': 'Olathe, Kansas, USA',
                        'name': 'Micro-Comm',
                        'size': 'Small',
                        'type': 'Manufacturer'}],
 'attack_vector': 'Unknown (opportunistic)',
 'customer_advisories': 'Micro-Comm notified clients on August 8 to update '
                        'passwords.',
 'data_breach': {'data_encryption': 'Data remained encrypted post-breach',
                 'data_exfiltration': 'Yes (posted on dark web)',
                 'number_of_records_exposed': '850,000 files',
                 'personally_identifiable_information': 'Employee names',
                 'sensitivity_of_data': 'Potentially aiding future attacks',
                 'type_of_data_compromised': 'Government customer details, '
                                             'employee names, product '
                                             'diagrams'},
 'date_detected': '2024-07-31',
 'date_publicly_disclosed': '2024-08-06',
 'description': 'US authorities are investigating a data breach at Micro-Comm, '
                'a small Kansas-based manufacturer of programmable logic '
                'controllers (PLCs) used in wastewater processing facilities. '
                'The attack was claimed by the ransomware group Barracuda, '
                'which posted nearly 850,000 files (644 GB) on August 6. The '
                'breach underscored vulnerabilities in local water systems and '
                'their supply chains.',
 'impact': {'brand_reputation_impact': 'Potential long-term cyber threat risks',
            'data_compromised': '850,000 files (644 GB)',
            'identity_theft_risk': 'Employee names exposed',
            'operational_impact': 'No operational compromise of water systems',
            'systems_affected': 'SCADAview CSX systems (200 exposed online)'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Highlights vulnerabilities in critical infrastructure '
                    'supply chains and risks from exposed SCADA systems.',
 'motivation': 'Financial',
 'post_incident_analysis': {'corrective_actions': 'Password updates, potential '
                                                  'future monitoring '
                                                  'enhancements',
                            'root_causes': 'Opportunistic ransomware attack, '
                                           'exposed SCADA systems'},
 'ransomware': {'data_encryption': 'Yes',
                'data_exfiltration': 'Yes (644 GB posted)',
                'ransomware_strain': 'Barracuda'},
 'recommendations': 'Update passwords, monitor for future threats, enhance '
                    'supply chain security for PLC vendors.',
 'references': [{'source': 'FBI'},
                {'source': 'CISA'},
                {'source': 'SentinelOne (Tom Hegel)'},
                {'source': 'Censys'}],
 'regulatory_compliance': {'regulatory_notifications': 'FBI, CISA warnings '
                                                       'issued'},
 'response': {'communication_strategy': 'Notified clients on August 8',
              'containment_measures': 'Limited malware attack, encrypted data '
                                      'remained secure',
              'law_enforcement_notified': 'FBI, CISA',
              'remediation_measures': 'Advised customers to update passwords'},
 'stakeholder_advisories': 'FBI and CISA advisories on PLC vulnerabilities and '
                           'AI exploitation risks.',
 'threat_actor': 'Barracuda (ransomware group)',
 'title': 'Cybersecurity Breach at Kansas Water Utility Tech Firm Exposes '
          'Critical Infrastructure Risks',
 'type': 'Ransomware, Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.