Two water-sector cyber stories broke a day apart. On 30 July 2026 the FBI warned that attackers were reaching internet-exposed programmable logic controllers at US water utilities, stripping monitoring and control in at least seven states. On 31 July, Kansas water-technology supplier Micro-Comm discovered a ransomware breach that leaked roughly 644 GB. They are not the same campaign, and the evidence separating them is already public.
What did the FBI warn about?
The FBI’s 30 July alert describes attackers reaching water and wastewater controllers directly over the internet, then changing their IP addresses and passwords to cause a loss of monitoring and control. The advisory names Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers, while noting that similar risk applies to other brands.
The consequences were physical. Utilities in at least seven states reported incidents to the FBI from 27 July onward, with reported effects including loss of pressure and flooding. At least one organisation found modified PLC project files, meaning the ladder logic controlling the process had been altered.
What the advisory does not describe is extortion. There is no ransom note, no leak site, and no payment demand in this campaign. That absence is the single most important fact for telling the two stories apart.
What happened to Micro-Comm?
Micro-Comm, a Kansas manufacturer of telemetry and control equipment used by water utilities, discovered a cyberattack on 31 July 2026. The ransomware group Barracuda claimed responsibility and published nearly 850,000 stolen files, about 644 GB, on 6 August. The incident was reported publicly on 26 August, which is when it collided with the water-sector news cycle.
Barracuda is a financially motivated operation, not a state-directed one. It followed the standard double-extortion pattern: steal data, demand payment, publish when the payment does not arrive. Ransomnews logs the incident in its confirmed dataset as an August 2026 attack on a US manufacturer.
Are the two campaigns connected?
No public evidence connects them, and on the decisive question there is evidence pointing the other way. Micro-Comm states that the breach did not expose customer passwords, credentials, or information that would allow Micro-Comm to remotely access its equipment. The FBI told the company the attack appeared opportunistic rather than specifically targeted. No agency has linked the two.
Four tests separate them cleanly.
| Test | Water PLC campaign | Micro-Comm breach |
|---|---|---|
| Objective | Disruption of process control | Extortion for payment |
| Target layer | Operational technology (PLC config, ladder logic) | Enterprise IT (file exfiltration) |
| Demand | None reported | Ransom demanded, 644 GB leaked when unpaid |
| Route to utilities | Direct internet exposure of controllers | Company reports no customer credentials or remote-access data exposed |
| Official characterisation | Active FBI advisory, seven or more states | FBI told the company it looked opportunistic |
The reason the two got bundled is chronological, not evidential. The FBI advisory landed on 30 July and Micro-Comm found its breach on 31 July. One day apart, one sector, and the word “water” in both headlines was enough.

Why “no credentials exposed” is not “no risk”
Ruling out the access path does not rule out the intelligence value. A supplier of water-sector telemetry equipment holds design documentation, network diagrams, customer lists, and configuration detail. None of that is a credential, and all of it is useful to an actor mapping which utilities run which controllers and how those controllers are reachable.
The accurate framing is therefore narrower than “unrelated” and wider than “connected”. The Micro-Comm breach was not the access vector for the PLC campaign, but 644 GB from a water-sector supplier is a plausible targeting aid for the next one. Both statements can be true at once, and most coverage this month has picked one and dropped the other.
Press coverage has also framed the breach against a backdrop of Iran-linked concern about US water infrastructure. That context belongs to the sector, not to this incident. Nothing in the reporting attributes the Micro-Comm ransomware to a state actor, and Barracuda’s behaviour is consistent with ordinary criminal extortion.
// Free tool
How does your own site score?
Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.
No signup. Nothing installed. We only request what your site already serves publicly.
What does the confirmed record show?
Ransomware is not what has been disrupting US water utilities in 2026. The Ransomnews confirmed-attack dataset holds 9,520 independently verified ransomware incidents from 2018 to the present. Of those, 244 hit organisations classified as utilities, and 11 of those fall in 2026. None of the 2026 utility incidents were in the United States.
That gap is the point. The pressure on American water systems this summer came from a campaign that does not encrypt, does not extort, and therefore does not appear in ransomware statistics at all. Anyone measuring water-sector risk by counting ransomware incidents would conclude 2026 was quiet.
Utilities also almost never pay. Across all 244 confirmed utility attacks in the dataset, exactly one records a confirmed ransom payment. For operators, that reframes the threat model: the leverage against a water utility is disruption and public pressure, not the prospect of a transfer.
There is a classification trap here worth naming. Micro-Comm is filed under manufacturing, because it makes equipment, not water. Any analyst filtering a ransomware dataset for “utilities” to assess water-sector exposure would miss the most consequential water-sector victim of the year. Sector taxonomies describe what an organisation is, not who depends on it, and supply-chain risk hides in that gap. You can query the underlying data yourself on the Ransomtracker, and browse operator profiles in our threat group catalogue.
What should water utilities do now?
Start with the FBI’s own mitigations, because they address the campaign that is actually causing outages. Disconnect PLCs from the public internet and place them behind a secure gateway. Set unique, complex device passwords, since default and reused credentials are what make internet-exposed controllers trivial to take. Restrict traffic with firewall rules and access control lists, put physical or software key switches into the run position to block unauthorised logic changes, and review PLC project files for modifications you did not make.
Keep the ability to run the plant manually. The reported harms in this campaign were loss of pressure and flooding, which are process outcomes, and the utilities that fared best were the ones that could operate without the automation layer while they recovered it.
Then treat the supplier relationship as part of your attack surface. Ask vendors what they hold about your environment, what they can reach remotely, and how they would tell you if they were breached. On the identity side, corporate credentials for utility staff circulate in infostealer logs long before anyone uses them, and you can check your own domain against that ecosystem with Stealercheck. For the enterprise side of the network, our business ransomware protection guide covers the detection layer.
Frequently asked questions
Was the Micro-Comm hack part of the attacks on US water systems?
No public evidence links them. The FBI told Micro-Comm its breach appeared opportunistic rather than targeted, and no agency has connected it to the campaign against water utility controllers.
Who attacked Micro-Comm?
A ransomware group called Barracuda claimed the attack and published about 644 GB of stolen files on 6 August 2026. Barracuda is financially motivated rather than state-directed.
Did attackers reach water utility control systems through Micro-Comm?
Micro-Comm states the breach did not expose customer passwords, credentials, or data enabling remote access to its equipment. No evidence indicates attackers reached customer control systems through the supplier.
Is the water PLC campaign ransomware?
No. The reported activity involves changing controller IP addresses, passwords and ladder logic to disrupt operations, with no ransom demand or data leak site. It is a disruption campaign, not an extortion one.
How many ransomware attacks have hit utilities?
The Ransomnews confirmed dataset records 244 ransomware attacks on utilities between 2018 and 2026, out of 9,520 confirmed incidents overall. Eleven fall in 2026, none of them in the United States.
Do water utilities pay ransoms?
Almost never. Exactly one of the 244 confirmed utility attacks in the dataset records a confirmed ransom payment, which suggests operators treat restoration as cheaper than negotiation.
Which controllers did the FBI name?
The alert names Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 series controllers. The FBI notes that comparable risk applies to internet-exposed controllers from other vendors.
Sources and further reading
- FBI, Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, 30 July 2026
- Reuters, Hack of water sector supplier draws FBI scrutiny as Iran-linked cyber concerns grow, 26 August 2026
- IBTimes, US water systems are already under cyberattacks, now a key technology supplier has been hacked too
- Cybersecurity Dive, What we know so far about the hacking campaign against US water systems
- Ransomnews, Ransomtracker confirmed-attack dataset
The Ransomnews Monthly
One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.
Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.
