Federal agents and cybersecurity officials are investigating a ransomware attack against Micro-Comm, a Kansas technology supplier for municipal water systems and wastewater treatment plants, after hackers leaked nearly 850,000 corporate files online.
The breach, which was disclosed on August 27, 2026, involved the unauthorized release of approximately 644 gigabytes of internal company data. Micro-Comm and the Federal Bureau of Investigation both confirmed that an inquiry into the incident is underway.
Micro-Comm operates out of Olathe, Kansas, a city located in Johnson County near Kansas City. The company manufactures hardware and software systems used by local utilities to control equipment, manage wastewater treatment processes, and maintain municipal water distribution networks.

A cybercrime organization calling itself Barracuda claimed responsibility for the extortion attack. The group stated that its operations are driven strictly by financial motives and said it receives no funding or direction from any foreign government.
Barracuda published the stolen data dump on August 6, 2026. A catalog of the leaked material compiled by eCrime.ch, a Swiss cybercrime intelligence platform, revealed that the files contain information regarding specific public sector clients, including local municipal authorities and a United States military facility.
The leaked files also include employee names, product information, and technical schematics for company hardware. Cybercrime tracking platforms like eCrime.ch monitor dark web leak sites to document stolen corporate data and alert affected organizations.
Stolen data and technical risks
Tom Hegel, a senior threat researcher at the cybersecurity company SentinelOne, stated that the publication of the documents does not indicate that operational control of any water utility was compromised. SentinelOne is an American cybersecurity vendor that tracks global threat actors and corporate network breaches.
Hegel warned, however, that the exposed technical diagrams and product details could allow other hackers to analyze Micro-Comm devices and design new cyberattacks against water infrastructure in the future.
Micro-Comm co-owner Jim Cote stated that company administrators first identified the network breach on July 31, 2026. Cote said the stolen files contained no sensitive access credentials, such as usernames or passwords, noting that customers store authentication data on their own local servers.
Cote added that the leaked material contained no information that would allow external actors to gain remote access to Micro-Comm devices installed at customer facilities.

Micro-Comm issued a security advisory to its client base on August 8, 2026, describing the incident as a limited malware attack. The company reported that sensitive internal data within the files remained encrypted, but recommended that customers update their system passwords as a precaution.
Internet exposure and SCADA systems
An investigation by Censys, an internet scanning and threat monitoring company, discovered that roughly 200 Micro-Comm SCADAview CSX systems across multiple American states are directly exposed to the public internet. SCADAview CSX is a supervisory software suite created by Micro-Comm to monitor and control industrial equipment.
Supervisory Control and Data Acquisition, or SCADA, refers to industrial control systems that process real-time data to monitor physical machinery at public utilities. Censys tracks global internet infrastructure to identify vulnerable and exposed devices online.
Dixon Land, a spokesman for the FBI office in Kansas City, stated that federal agents are in contact with Micro-Comm and are coordinating with partner law enforcement agencies. The United States Cybersecurity and Infrastructure Security Agency, known as CISA, referred all inquiries regarding the breach back to the company.

Cote stated that the FBI informed Micro-Comm that the intrusion was an opportunistic cyberattack rather than a targeted strike aimed specifically at the business. Cote also emphasized that the breach was unrelated to recent news reports concerning cyberattacks on American water facilities.
Parallel Iranian cyber campaign
The Micro-Comm breach coincided with a series of cyberattacks in late July 2026 that targeted programmable logic controllers, or PLCs, in Minnesota and at least six other American states. PLCs are compact digital computers used in industrial environments to automate machinery such as pumps and valves.
Cybersecurity experts assess that the July attacks were part of an ongoing cyber campaign linked to Iran. However, investigators have found no evidence connecting the Micro-Comm incident to the Iranian operation.
On July 30, 2026, the FBI and CISA issued a joint advisory warning that hackers were targeting PLCs produced by Rockwell Automation in the United States, Schneider Electric in France, and Siemens in Germany. CISA is the primary federal agency charged with safeguarding American critical infrastructure against digital threats.
On August 19, 2026, CISA announced that malicious actors were employing artificial intelligence tools to facilitate attacks on Siemens industrial devices. Siemens subsequently stated that it was working with CISA and assured customers that its hardware remains secure.
The parallel cases illustrate the challenge facing federal authorities in safeguarding digital networks across critical infrastructure, including the extended network of equipment manufacturers and technology suppliers that support public utilities.
