Massive Cyberattack on US Water Control Firm Exposes Critical Infrastructure Risks
In late July, Micro-Comm, a small programmable logic controller (PLC) manufacturer based in Olathe, Kansas, suffered a major cyber breach by the ransomware group Barracuda. The attack exposed nearly 850,000 sensitive files totaling approximately 644 gigabytes, including employee names, critical product diagrams, and confidential client information from government and military entities. Barracuda published the stolen data in early August, triggering widespread concern about vulnerabilities in the US water and sewage infrastructure supply chain.
Despite the breach's scale, Micro-Comm reported no operational damage due to prior encryption and the absence of stored customer passwords on its servers. The FBI confirmed the incident was an opportunistic attack rather than part of a coordinated hostile campaign, although it coincided with Iranian cyberattacks on various targets and phishing attempts against Israeli journalists. Cybersecurity experts warn that the leaked technical diagrams could serve as blueprints for future hostile attacks on water facilities.
Micro-Comm is cooperating closely with the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), urging all customers to immediately change their passwords. This incident highlights how even a small company in the US heartland can become a critical vulnerability point in national security. It also mirrors ongoing daily Iranian cyber threats against Israeli water systems, underscoring the global nature of such risks.
Experts emphasize that the threat is tangible, not theoretical, as past attempts to disrupt water systems have occurred. The detailed stolen information could facilitate targeted attacks capable of disrupting water supplies to millions. While law enforcement continues investigations, the exposure of this data marks a significant escalation in cyber risks to essential infrastructure worldwide.