World
US Probe into 850,000-File Breach at Kansas Water Infrastructure Firm
US authorities are investigating a cyberattack on Micro-Com, a Kansas-based maker of programmable logic controllers for wastewater facilities, which leaked 850,000 files totaling 644 GB—though officials say the incident was opportunistic and unrelated to recent Iranian-linked attacks on water systems.

American authorities are investigating a data breach targeting Micro-Com, a small Kansas-based company that manufactures industrial control technologies for water infrastructure. The incident highlights cybersecurity risks facing critical infrastructure—but investigators stress that Micro-Com, located in Olathe, Kansas, was not part of a broader campaign targeting water treatment facilities in Minnesota and at least six other states, which US cybersecurity experts have linked to Iran.
The company, the Federal Bureau of Investigation (FBI), and cybersecurity agencies confirmed the attack occurred against Micro-Com. It had not been publicly reported prior to this disclosure. The hacking group Baracuda claimed responsibility, describing itself as a relatively new ransomware operation motivated solely by financial gain and asserting it receives no government backing.
On August 6, Baracuda published what it described as approximately 850,000 files belonging to Micro-Com, with a total volume of roughly 644 gigabytes. Micro-Com produces programmable logic controllers (PLCs)—industrial computers used to manage machinery within critical infrastructure networks—and its devices are deployed at wastewater treatment facilities.
The breach underscores the layered challenges involved in securing local water systems and their supply-chain vendors amid a rising number of cyberattacks targeting embedded computer systems in US critical infrastructure.
The intrusion occurred during a wave of PLC-targeted attacks in late July that affected facilities in Minnesota and at least six additional states. Cybersecurity experts assess those incidents as components of a longer-running Iranian-linked cyber campaign.
Targeting Critical Infrastructure
On July 30, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) jointly issued a warning that hackers were targeting PLCs manufactured by Rockwell Automation, Schneider Electric, and Siemens.
CISA stated on August 19 that the attackers are using artificial intelligence to streamline their operations against Siemens equipment. Siemens later affirmed it is cooperating with CISA and reiterated that its products are secure.
Dixon Land, FBI spokesperson for the Kansas City field office, confirmed in an email message that the bureau is in contact with Micro-Com regarding the breach and is coordinating with other law enforcement agencies. CISA referred all inquiries about the incident to Micro-Com.
Jim Cote, one of the company’s owners, said in an interview that Micro-Com discovered the breach on July 31.
Cote added that the files released by the hackers did not include sensitive information such as user passwords, client-held credentials, or data related to Micro-Com’s remote access capabilities for its devices.
In a customer advisory issued August 8, the company characterized the incident as a “limited malware attack” and stated that any sensitive information contained in the compromised files was encrypted. It further clarified that the breach “is in no way related to the water system intrusions currently being reported in the news.”
Cote noted that the FBI informed Micro-Com the data breach was an opportunistic attack—not one specifically directed at the company—and that Micro-Com advised customers to change passwords as a precautionary measure.
According to internet monitoring firm SenseCyber, approximately 200 of Micro-Com’s SCADAview CSX systems—among its product offerings—are accessible online across US states.
An inventory of the leaked files, compiled by E-Crime—a platform conducting cybercrime research for designated government clients—includes listings for local government entities and a US military installation. It also contains employee names and product-related materials, including technical illustrations.
Tom Hegel, principal threat researcher at cybersecurity firm SentinelOne, emphasized that the publication of these files does not indicate that any water system has suffered an operational compromise—but acknowledged the data could assist adversaries in future targeting efforts.





