
A ransomware group calling itself Barracuda posted about 850,000 files stolen from Micro-Comm Inc., a Kansas manufacturer whose equipment controls water and wastewater systems across the country, and U.S. authorities are now investigating the breach amid growing concern about Iran-linked hacking of American water infrastructure. Micro-Comm, based in Olathe, discovered the intrusion on July 31, and the FBI has been in contact with the company about it ever since.
According to Reuters, Barracuda publicly posted the leak on August 6, listing roughly 850,000 files totaling roughly 644 gigabytes and demanding a starting price of $30,000 for the dataset, a detail also confirmed by DeXpose. Researchers at ecrime.ch, cited in the Reuters report, identified specific government customers, employee names, product diagrams and even a U.S. military facility among the exposed file list. The FBI told Micro-Comm the breach appears to have been an opportunistic attack rather than one specifically targeted at the company, and the bureau said it is coordinating with other law enforcement agencies as the investigation continues.
Barracuda is described in the reporting as a relatively new ransomware group that is not government sponsored and is motivated by profit rather than politics. Still, the timing has raised alarm. Tom Hegel, a cybersecurity expert quoted in the same report, said the exposed information could help hackers over the long term, though he also cautioned that the release of files did not mean any water system had been operationally compromised.
Micro-Comm's Response and What Was — And Wasn't — Exposed
In a customer newsletter dated August 8, Micro-Comm described the incident as a limited malware attack and said the released files did not contain data related to its ability to remotely access customer devices. The company said any sensitive information within the files was encrypted and that the breach was unrelated to the separate wave of water-system hacks being reported around the same time. Micro-Comm also said the files did not include sensitive material such as user passwords and credentials, noting that customers themselves store those credentials, and the company has recommended that customers change their passwords as a precaution.
The broader discussion also considers cyber disruptions involving municipal services as a local precedent.
Micro-Comm supplies equipment for water and wastewater systems, according to the company. Censys data cited in the Reuters reporting found roughly 200 SCADAview CSX systems accessible directly from the internet across U.S. states, a detail that underscores how exposed some of this equipment already is before any breach occurs.
A Broader Pattern of Attacks on Water Sector Hardware
The Micro-Comm breach lands amid a string of federal warnings about attacks on the water sector's industrial hardware. On July 30, the FBI and EPA issued a joint public service announcement warning that water and wastewater utilities in at least seven states, including Minnesota, had experienced operational disruptions after attackers altered IP addresses and passwords on internet-facing Rockwell Automation programmable logic controllers, according to the FBI. Federal authorities noted that standardized network setups deployed by third-party integrators allowed the same exploits to be replicated across multiple customers.
Days earlier, on July 22, U.S. security agencies updated a joint advisory confirming that Iranian-affiliated cyber groups had expanded their targeting beyond Rockwell equipment to include Schneider Electric and Siemens systems, using legitimate vendor engineering software to download project files, per CISA. Cybersecurity experts believe the late-July attacks were part of a longer-running Iranian-affiliated campaign against U.S. water infrastructure. Hoodline previously reported on hacked Georgia water controls tied to that same wave of intrusions.
AI-Assisted Reconnaissance and a History of Iranian Targeting
Then, on August 19, federal security agencies released a further advisory warning that threat actors are actively deploying AI-generated exploitation scripts disguised as legitimate monitoring software to conduct reconnaissance against Siemens S7 Series PLCs, the CISA notice stated. The advisory addressed Siemens S7 Series PLCs at water facilities, while CISA itself referred further questions on the Micro-Comm matter to the company.
The current activity echoes a documented history of Iranian state-linked targeting of American water infrastructure. In November 2023, the IRGC-affiliated group CyberAv3ngers compromised operational control systems at U.S. water utilities, including the Municipal Authority of Aliquippa in Pennsylvania, by exploiting internet-exposed Israeli-made Unitronics controllers, defacing human-machine interface screens to lock operators out, per the same CISA advisory. And in February 2021, an unauthorized actor briefly gained remote access to the municipal water treatment plant in Oldsmar, Florida, attempting to raise sodium hydroxide levels to dangerous concentrations before a plant operator intervened manually, according to the New Jersey Cybersecurity and Communications Integration Cell. Dixon Land, a spokesperson for the FBI's Kansas City field office, has been named in connection with the Micro-Comm case as the bureau's investigation continues.
Why Federal Rules Remain Voluntary
Underlying all of this is the question of water-sector regulation. The EPA has addressed cybersecurity requirements for water systems.
Under Section 1433 of the Safe Drinking Water Act, community water systems serving more than 3,300 people must conduct Risk and Resilience Assessments and update Emergency Response Plans every five years, per the EPA. The consequences of that gap show up in the agency's own inspection data: an EPA enforcement alert issued in May 2024 found that more than 70 percent of inspected U.S. community drinking water systems failed to comply with basic Safe Drinking Water Act cybersecurity requirements, often leaving default passwords unchanged or relying on unencrypted single logins. Federal inspectors described the gaps as leaving critical equipment vulnerable to internet-based intrusions. The Congressional Research Service said that in 2024 the EPA identified "alarming cybersecurity vulnerabilities at drinking water systems across the country."
That patchwork of voluntary guidance, rather than mandatory technical rules, is part of why incidents like the Micro-Comm breach draw such close federal attention even when a company insists the leaked data poses no immediate operational risk. With Iranian-affiliated actors already documented probing similar equipment and AI-assisted reconnaissance tools now in the mix, cybersecurity experts continue to watch whether criminal leaks like Barracuda's dump could eventually be exploited by more sophisticated, state-linked actors down the line.







-4.webp?w=1000&h=1000&fit=crop&crop:edges)

