US water sector supplier hack draws FBI scrutiny as Iran-linked cyber concerns grow
Cote said the FBI told the company the data breach was an opportunistic attack not specifically targeting Micro-Comm, and the company recommended that customers change passwords out of caution.
The FBI is investigating a data breach at Micro-Comm, a Kansas-based company that manufactures programmable logic controllers (PLCs) for water utility technology. The breach, discovered on July 31, involved nearly 850,000 company files totaling around 644 gigabytes of data. The files were reportedly released by a ransomware group claiming to be motivated by profit, not government affiliation.
Micro-Comm makes PLCs used in critical infrastructure networks, specifically wastewater processing facilities. The company's PLCs were targeted among hacks in Minnesota and six other states during a late July hacking spree. While the FBI and CISA warned of potential threats to PLCs from US-based technology companies like Rockwell Automation, France's Schneider Electric, and Germany's Siemens, Micro-Comm was not directly linked to the Iranian-affiliated cyber campaign.
The company stated that the released files did not contain sensitive information such as user passwords or credentials, which are stored by customers or data related to Micro-Comm's remote access capabilities. Micro-Comm advised customers to change their passwords as a precaution. The breach was described as opportunistic, not specifically targeting Micro-Comm.
The incident highlights the growing cybersecurity threats to US water systems and the vendors that support them. Experts noted that the breach might help hackers in the long term by providing them with valuable information about government customers, including localities and a US military facility.
Written by urgent.news from Jerusalem Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.