Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Micro-Comm hack is separate from the US water attacks

Neringa MacijauskaitėBy Neringa MacijauskaitėSeptember 1, 2026Updated:September 1, 2026No Comments8 Mins Read100 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Ransomnews cover: one day apart, two water attacks, not one campaign. 1 of 244 confirmed utility ransomware attacks recorded a paid ransom
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Two water-sector cyber stories broke a day apart. On 30 July 2026 the FBI warned that attackers were reaching internet-exposed programmable logic controllers at US water utilities, stripping monitoring and control in at least seven states. On 31 July, Kansas water-technology supplier Micro-Comm discovered a ransomware breach that leaked roughly 644 GB. They are not the same campaign, and the evidence separating them is already public.

What did the FBI warn about?

The FBI’s 30 July alert describes attackers reaching water and wastewater controllers directly over the internet, then changing their IP addresses and passwords to cause a loss of monitoring and control. The advisory names Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers, while noting that similar risk applies to other brands.

The consequences were physical. Utilities in at least seven states reported incidents to the FBI from 27 July onward, with reported effects including loss of pressure and flooding. At least one organisation found modified PLC project files, meaning the ladder logic controlling the process had been altered.

What the advisory does not describe is extortion. There is no ransom note, no leak site, and no payment demand in this campaign. That absence is the single most important fact for telling the two stories apart.

What happened to Micro-Comm?

Micro-Comm, a Kansas manufacturer of telemetry and control equipment used by water utilities, discovered a cyberattack on 31 July 2026. The ransomware group Barracuda claimed responsibility and published nearly 850,000 stolen files, about 644 GB, on 6 August. The incident was reported publicly on 26 August, which is when it collided with the water-sector news cycle.

Barracuda is a financially motivated operation, not a state-directed one. It followed the standard double-extortion pattern: steal data, demand payment, publish when the payment does not arrive. Ransomnews logs the incident in its confirmed dataset as an August 2026 attack on a US manufacturer.

Are the two campaigns connected?

No public evidence connects them, and on the decisive question there is evidence pointing the other way. Micro-Comm states that the breach did not expose customer passwords, credentials, or information that would allow Micro-Comm to remotely access its equipment. The FBI told the company the attack appeared opportunistic rather than specifically targeted. No agency has linked the two.

Four tests separate them cleanly.

TestWater PLC campaignMicro-Comm breach
ObjectiveDisruption of process controlExtortion for payment
Target layerOperational technology (PLC config, ladder logic)Enterprise IT (file exfiltration)
DemandNone reportedRansom demanded, 644 GB leaked when unpaid
Route to utilitiesDirect internet exposure of controllersCompany reports no customer credentials or remote-access data exposed
Official characterisationActive FBI advisory, seven or more statesFBI told the company it looked opportunistic

The reason the two got bundled is chronological, not evidential. The FBI advisory landed on 30 July and Micro-Comm found its breach on 31 July. One day apart, one sector, and the word “water” in both headlines was enough.

Timeline showing the water utility PLC campaign and the Micro-Comm ransomware breach running in parallel from 27 July to 26 August 2026 without intersecting
The two threads run in parallel through the same five weeks. The PLC campaign begins on 27 July and produces an FBI advisory on 30 July. Micro-Comm discovers its breach on 31 July, is leaked on 6 August, and is reported on 26 August. No public evidence connects the tracks.

Why “no credentials exposed” is not “no risk”

Ruling out the access path does not rule out the intelligence value. A supplier of water-sector telemetry equipment holds design documentation, network diagrams, customer lists, and configuration detail. None of that is a credential, and all of it is useful to an actor mapping which utilities run which controllers and how those controllers are reachable.

The accurate framing is therefore narrower than “unrelated” and wider than “connected”. The Micro-Comm breach was not the access vector for the PLC campaign, but 644 GB from a water-sector supplier is a plausible targeting aid for the next one. Both statements can be true at once, and most coverage this month has picked one and dropped the other.

Press coverage has also framed the breach against a backdrop of Iran-linked concern about US water infrastructure. That context belongs to the sector, not to this incident. Nothing in the reporting attributes the Micro-Comm ransomware to a state actor, and Barracuda’s behaviour is consistent with ordinary criminal extortion.

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

What does the confirmed record show?

Ransomware is not what has been disrupting US water utilities in 2026. The Ransomnews confirmed-attack dataset holds 9,520 independently verified ransomware incidents from 2018 to the present. Of those, 244 hit organisations classified as utilities, and 11 of those fall in 2026. None of the 2026 utility incidents were in the United States.

That gap is the point. The pressure on American water systems this summer came from a campaign that does not encrypt, does not extort, and therefore does not appear in ransomware statistics at all. Anyone measuring water-sector risk by counting ransomware incidents would conclude 2026 was quiet.

Utilities also almost never pay. Across all 244 confirmed utility attacks in the dataset, exactly one records a confirmed ransom payment. For operators, that reframes the threat model: the leverage against a water utility is disruption and public pressure, not the prospect of a transfer.

There is a classification trap here worth naming. Micro-Comm is filed under manufacturing, because it makes equipment, not water. Any analyst filtering a ransomware dataset for “utilities” to assess water-sector exposure would miss the most consequential water-sector victim of the year. Sector taxonomies describe what an organisation is, not who depends on it, and supply-chain risk hides in that gap. You can query the underlying data yourself on the Ransomtracker, and browse operator profiles in our threat group catalogue.

What should water utilities do now?

Start with the FBI’s own mitigations, because they address the campaign that is actually causing outages. Disconnect PLCs from the public internet and place them behind a secure gateway. Set unique, complex device passwords, since default and reused credentials are what make internet-exposed controllers trivial to take. Restrict traffic with firewall rules and access control lists, put physical or software key switches into the run position to block unauthorised logic changes, and review PLC project files for modifications you did not make.

Keep the ability to run the plant manually. The reported harms in this campaign were loss of pressure and flooding, which are process outcomes, and the utilities that fared best were the ones that could operate without the automation layer while they recovered it.

Then treat the supplier relationship as part of your attack surface. Ask vendors what they hold about your environment, what they can reach remotely, and how they would tell you if they were breached. On the identity side, corporate credentials for utility staff circulate in infostealer logs long before anyone uses them, and you can check your own domain against that ecosystem with Stealercheck. For the enterprise side of the network, our business ransomware protection guide covers the detection layer.

Frequently asked questions

Was the Micro-Comm hack part of the attacks on US water systems?

No public evidence links them. The FBI told Micro-Comm its breach appeared opportunistic rather than targeted, and no agency has connected it to the campaign against water utility controllers.

Who attacked Micro-Comm?

A ransomware group called Barracuda claimed the attack and published about 644 GB of stolen files on 6 August 2026. Barracuda is financially motivated rather than state-directed.

Did attackers reach water utility control systems through Micro-Comm?

Micro-Comm states the breach did not expose customer passwords, credentials, or data enabling remote access to its equipment. No evidence indicates attackers reached customer control systems through the supplier.

Is the water PLC campaign ransomware?

No. The reported activity involves changing controller IP addresses, passwords and ladder logic to disrupt operations, with no ransom demand or data leak site. It is a disruption campaign, not an extortion one.

How many ransomware attacks have hit utilities?

The Ransomnews confirmed dataset records 244 ransomware attacks on utilities between 2018 and 2026, out of 9,520 confirmed incidents overall. Eleven fall in 2026, none of them in the United States.

Do water utilities pay ransoms?

Almost never. Exactly one of the 244 confirmed utility attacks in the dataset records a confirmed ransom payment, which suggests operators treat restoration as cheaper than negotiation.

Which controllers did the FBI name?

The alert names Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 series controllers. The FBI notes that comparable risk applies to internet-exposed controllers from other vendors.

Sources and further reading

  • FBI, Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, 30 July 2026
  • Reuters, Hack of water sector supplier draws FBI scrutiny as Iran-linked cyber concerns grow, 26 August 2026
  • IBTimes, US water systems are already under cyberattacks, now a key technology supplier has been hacked too
  • Cybersecurity Dive, What we know so far about the hacking campaign against US water systems
  • Ransomnews, Ransomtracker confirmed-attack dataset

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleLove Electric driver data for sale: NI, licence numbers
Next Article The Town 2025 ticketing data sold as a Ticketmaster breach
Neringa Macijauskaitė
  • LinkedIn

Neringa Macijauskaitė is an information security researcher covering threat intelligence and cybercrime for Ransomnews. She has worked as an information security researcher, conducting threat intelligence investigations, tracking emerging cyber threats, and monitoring for exposed systems and online vulnerabilities. She is also part of the crew behind BSides Vilnius, the community-run security conference in Lithuania.

Related Posts

The Town 2025 ticketing data sold as a Ticketmaster breach

September 3, 2026

Love Electric driver data for sale: NI, licence numbers

August 28, 2026

Live Stripe keys for 659 merchants, published for free

August 18, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.