Skip to main content
Get our mobile app
Download on the App StoreGet it on Google Play

Critical Infrastructure at Risk

Cyberattack Exposes Water System Weaknesses

A breach at Micro-Comm, a small U.S. manufacturer of water system controllers, leaked nearly 850,000 sensitive files, raising urgent concerns about the security of critical infrastructure as the FBI investigates

Desalination plants in Israel

A cyberattack on a small Kansas company has exposed alarming weaknesses in America's water infrastructure security. Micro-Comm, a manufacturer of programmable logic controllers (PLCs) that operate water and wastewater facilities across the United States, was breached in late July by the Barracuda ransomware group.

According to an exclusive Reuters report, the breach exposed nearly 850,000 files totaling approximately 644 gigabytes of data. The leaked materials included employee names, critical product diagrams, and sensitive customer information, including government and military entities. The ransomware group published the stolen data in early August, creating what cybersecurity experts describe as a digital earthquake that threatens to expose vulnerabilities in essential systems nationwide.

The Barracuda group, which the FBI assesses operates purely for financial gain without state backing, successfully infiltrated the company's systems and extracted massive quantities of information. Despite the breach's enormous scope, Micro-Comm officials emphasized that operational damage was prevented through early encryption measures and the company's policy of not storing customer passwords on its servers.

The FBI officially confirmed that the attack was opportunistic rather than part of a coordinated hostile campaign. This determination comes despite the sensitive timing, which coincided with separate Iranian cyberattacks against various targets, including recently reported phishing attempts targeting Israeli journalists.

While physical systems remained intact, cybersecurity experts are issuing stark warnings: the stolen diagrams and technical information could serve as a dangerous blueprint for hostile actors planning future attacks. The company, working closely with the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), has urged all customers to change passwords immediately.

Desalination plants in Israel
Desalination plants in Israel ( Yitzhak Harari, Flash90)

The incident serves as a glaring warning that even a small company in the American heartland can suddenly become the most dangerous gateway to national security threats. As recently reported, Israel also faces daily Iranian cyberattacks on water systems, with the National Cyber Directorate confirming that "Israel experiences cyberattacks across all sectors on a daily basis."

The Kansas case demonstrates how a single weak link in the supply chain can endanger entire critical infrastructure networks. The leaked diagrams and technical information could enable future attackers to understand precisely how control systems operate and plan targeted attacks capable of disrupting water supplies to millions of citizens.

Cybersecurity officials stress that the threat is far from theoretical. Past incidents have already documented attempts by attackers to compromise water systems, and detailed information like what was leaked could significantly facilitate such attacks. While the company continues cooperating with law enforcement authorities, the damage is done, the information is out there, and the next threat may only be a matter of time.

Ready for more?

Join our newsletter to receive updates on new articles and exclusive content.

We respect your privacy and will never share your information.

Enjoyed this article?

Yes (20)
No (1)
Follow Us:

Unmissable content


Loading comments...

Also of Interest