Micro-Comm
Incident posture
Linked entities
- Victim
- Micro-Comm
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Micro-Comm, a Kansas-based maker of programmable logic controllers for wastewater processing, confirmed a data breach after a ransomware group called Barracuda claimed responsibility and released roughly 850,000 files totaling about 644 gigabytes. The company said the breach was discovered soon after the attack and that the exposed data did not include user passwords, credentials or information enabling remote access to its devices. The company told customers the incident was a limited malware attack with any sensitive information encrypted and stated it was unrelated to the concurrent water‑system hacks reported elsewhere. The FBI described the intrusion as opportunistic and not specifically targeted, while researchers noted the leaked material could assist future attacks despite no immediate operational impact on water systems.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 31 2026 Jim Cote, a co‑owner of Micro‑Comm in Olathe, Kansas, reported that the company had discovered a data breach. The ransomware group Barracuda claimed responsibility on August 6, stating that it had posted nearly 850,000 company files amounting to roughly 644 gigabytes of data. Micro‑Comm and the FBI confirmed the attack, noting that the breach occurred during a late‑July wave of intrusions targeting programmable logic controllers in Minnesota and at least six other states. The company’s SCADAview CSX product, with approximately 200 units accessible from the internet according to Censys, was among the systems referenced in the exposed files.
FBI and CISA had issued warnings on July 30 about hackers targeting PLCs from Rockwell Automation, Schneider Electric, and Siemens, and CISA noted on August 19 that attackers were using AI to facilitate assaults on Siemens equipment. Micro‑Comm told customers in an August 8 newsletter that it had experienced a limited malware attack and that any sensitive information in the released files was encrypted. The firm emphasized that the breach was “in no way related to water system hacks currently being reported on the news.” A compilation of the leaked data by eCrime referenced specific government customers, including localities and a U.S. military facility, employee names, and product diagrams.
In response, the FBI’s Kansas City field office, through spokesperson Dixon Land, confirmed contact with Micro‑Comm and coordination with other law‑enforcement agencies. Jim Cote said the FBI characterized the incident as an opportunistic attack not specifically aimed at Micro‑Comm, and the company advised customers to change passwords as a precautionary measure. Senior threat researcher Tom Hegel of SentinelOne stated that the file release did not indicate any water‑system operational compromise, though the information could potentially aid future hacking efforts. No further details about remediation timelines or additional impacts were provided in the source material.
Sources
Sources available to members: 1 source.