Skip to content
RansomwareUnknown

Micro-Comm ransomware attack draws FBI scrutiny over water-sector risk

Kansas-based water and wastewater control-systems supplier Micro-Comm was hit by the Barracuda ransomware group, which claimed to have stolen roughly 644 GB of data, prompting FBI scrutiny amid heightened concern over attacks on the U.S. water sector.

Victim
Micro-Comm, Inc.

On 26 August 2026, reporting revealed that the FBI was scrutinizing a ransomware attack on Micro-Comm, Inc., an industrial-automation company based in Olathe, Kansas, that supplies water and wastewater control systems, control panels, micro-controllers and SCADA software. The attention came against a backdrop of heightened concern over intrusions targeting the U.S. water sector.

Micro-Comm discovered the breach on 31 July 2026, and the Barracuda ransomware group subsequently listed the company on its leak site, claiming to have stolen nearly 850,000 files totaling roughly 644 GB of data, with a ransom demand starting around $30,000. The group's file listing reportedly referenced specific government customers โ€” including local governments and a U.S. military facility โ€” along with employee information and product diagrams. Micro-Comm said sensitive user credentials and remote-access information had not been compromised.

What happened

What set this incident apart from the 2026 attacks on individual water utilities is that the victim is a supplier of the technology used to operate water infrastructure, rather than an operator itself. That supply-chain position is what drew federal interest: stolen product diagrams and customer references could, in the wrong hands, aid reconnaissance against downstream water and wastewater systems.

Why it matters

The Micro-Comm breach highlights the systemic risk in operational-technology supply chains serving critical infrastructure. Compromising a single control-systems vendor can yield sensitive technical detail about many utilities at once, making OT suppliers a high-value target even when their direct ransom demands are modest.

Financial impact

Reported costs in USD

Ransom demanded
$30.0K
Ransom paid
Refused

    Timeline

    1. Micro-Comm discovers the breach of its systems.

    2. The Barracuda ransomware group lists Micro-Comm as a victim and publishes stolen-file claims.

    3. Reporting reveals the FBI is scrutinizing the hack given the supplier's role in U.S. water infrastructure.

    Sources

    1. socradar.iohttps://socradar.io/data-breach/micro-comm-inc-barracuda-ransomware-2026/
    2. kelo.comhttps://kelo.com/2026/08/26/exclusive-hack-of-water-sector-supplier-draws-fbi-scrutiny-as-iran-linked-cyber-concerns-grow/
    3. ransomware.livehttps://ransomware.live/id/TWljcm8tQ29tbSBJbmMuQEJhcnJhY3VkYQ==

    Related incidents

    RansomwareContained

    Schneider Electric Sustainability Business Cactus ransomware (2024)

    Cactus ransomware operators hit Schneider Electric's Sustainability Business division, taking the Resource Advisor consulting platform offline and exfiltrating approximately 1.5 TB of data โ€” including passport scans and signed NDAs from customers like Hilton, PepsiCo, and Walmart.

    Victim
    Schneider Electric โ€” Sustainability Business division
    RansomwareContained

    Foxconn Nitrogen ransomware breach (2026)

    The Nitrogen ransomware group claimed on its dark-web leak site that it had stolen over 11 million files from Foxconn's North American facilities, including confidential information belonging to customers Apple, Dell, Google, Intel, Nvidia, and Sony. Foxconn said affected factories were resuming normal production.

    Victim
    Foxconn (Hon Hai Precision Industry)