OLATHE, KANSAS — The Federal Bureau of Investigation and Micro-Comm confirmed a data breach at the company’s facility in Olathe, Kansas. Micro-Comm discovered the breach on July 31, 2026.

Micro-Comm makes programmable logic controllers (PLCs) used to control machinery in wastewater processing facilities. Internet-monitoring firm Censys reported that roughly 200 of Micro-Comm's SCADAview CSX systems in use in U.S. states are accessible from the internet.

Jim Cote, a co-owner of Micro-Comm, stated that the FBI told the company the data breach was an opportunistic attack not specifically targeting Micro-Comm. "The breach was in no way related to water system hacks currently being reported on the news." Micro-Comm stated.

Dixon Land, a spokesperson for the FBI’s Kansas City field office, said the FBI was in contact with Micro-Comm about the hack and coordinating with other law enforcement agencies. Cote said the files released by the hackers did not contain sensitive information such as user passwords and credentials or data related to Micro-Comm's ability to remotely access its devices.

Cybercrime research platform eCrime gathered a list of files referring to specific government customers, including localities and a U.S. military facility, employee names, and product information such as diagrams. Tom Hegel, a senior threat researcher at cybersecurity firm SentinelOne, said the release of files did not mean any water system was operationally compromised, but the information could help hackers in the long term.

Timeline

The Cybersecurity and Infrastructure Security Agency (CISA) observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems Sector in July 2026. The FBI and CISA warned on July 30, 2026, that hackers were targeting PLCs from Rockwell Automation, Schneider Electric, and Siemens.

Barracuda posted nearly 850,000 company files with roughly 644 gigabytes of data on August 6, 2026. Micro-Comm told customers in an August 8, 2026 newsletter that it experienced a limited malware attack and any sensitive information in the files was encrypted.

What's New

The Cybersecurity and Infrastructure Security Agency (CISA) observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems Sector in July 2026. U.S. intelligence believes Iran is likely behind the largely opportunistic attacks on water providers.

At least 12 states were affected by the water sector cyberattacks, including Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. The cyberattacks on water systems did not cause any significant disruption.

Why It Matters

Micro-Comm produces programmable logic controllers used in wastewater processing, placing the company within a sector facing increased scrutiny. CISA is observing an increase in threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems Sector.

The breach occurred as federal agencies issued warnings about threats to industrial control systems. While the FBI characterized the incident as opportunistic, the release of company data illustrates the potential risks to infrastructure suppliers even when operational controls remain secure.