DistantNews
Support us
๐Ÿ‡ฎ๐Ÿ‡ฑ Israel /Technology

US water sector supplier hack draws FBI scrutiny as Iran-linked cyber concerns grow

From Jerusalem Post · () English

Summarized and contextualized by DistantNews.

At a glance

News Named sources Under investigation
  • US authorities are investigating a data breach at Kansas-based water utility tech supplier Micro-Comm.
  • The breach, claimed by ransomware group Barracuda, occurred during a spate of hacks targeting water plant PLCs in multiple states.
  • While Micro-Comm's breach is not believed to be part of the Iran-linked campaign, it highlights infrastructure cybersecurity vulnerabilities.

U.S. authorities, including the FBI, are investigating a data breach at Micro-Comm, a small supplier of water utility technology based in Olathe, Kansas. The company, which manufactures programmable logic controllers (PLCs) used in critical infrastructure, experienced the breach on July 31. Ransomware group Barracuda claimed responsibility, posting a large volume of company files online on August 6.

This incident occurred amidst a series of cyberattacks targeting PLCs in water facilities across Minnesota and at least six other states since late July. Cybersecurity experts suspect these attacks are part of a prolonged cyber campaign linked to Iran. The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) had previously issued warnings about hackers targeting PLCs from various international manufacturers, noting the use of AI to enhance attacks on Siemens equipment.

opportunistic attack

โ€” FBIThe FBI reportedly informed Micro-Comm that the data breach was not specifically targeted at their company.

While Micro-Comm's breach is reportedly an "opportunistic attack" and not directly linked to the suspected Iranian-affiliated campaign, it underscores the growing complexity and vulnerability of securing local U.S. water systems and their vendors. The company stated that the released files did not contain sensitive user passwords or credentials, and that any sensitive information was encrypted. Micro-Comm also informed customers that the breach was "in no way related to water system hacks currently being reported on the news."

The FBI is coordinating with Micro-Comm and other law enforcement agencies regarding the breach. CISA referred inquiries to the company. Jim Cote, a co-owner of Micro-Comm, mentioned that the FBI indicated the attack was not specifically targeted at their company. Out of an abundance of caution, the company recommended that customers change their passwords.

in no way related to water system hacks currently being reported on the news.

โ€” Micro-CommThe company communicated to its customers that its breach was separate from ongoing water system hacks.
DistantNews Editorial

Originally published by Jerusalem Post. Summarized and contextualized by our editorial team with added local perspective. Read our editorial standards.