644 GB Stolen From Water Infrastructure Supplier — FBI Investigates Micro-Comm Breach
- The Mess: Ransomware group Barracuda claims it stole roughly 850,000 files totaling 644 GB from Micro-Comm, a U.S. supplier of PLC and SCADA technology used in wastewater facilities. The FBI is investigating the breach, but there is no evidence that attackers gained operational control of water plants.
- The Damage: The leaked data reportedly includes technical documentation, customer information and system diagrams that could give attackers a detailed map of infrastructure used by water and wastewater operators.
- The Fix: Water utilities using Micro-Comm technology should review exposed systems, rotate credentials as a precaution and make sure PLCs and SCADA equipment are not directly reachable from the public Internet.
This one is nasty for a reason that has nothing to do with the size of the company.
Micro-Comm isn’t a household name.
It doesn’t need to be.
The company makes technology used inside water and wastewater infrastructure.
And someone just dumped a huge amount of its internal data online.
644 GB of Data
The ransomware group Barracuda claims responsibility for the attack.
On August 6, the group published what it described as approximately 850,000 Micro-Comm files, totaling around 644 GB.
Micro-Comm discovered the intrusion on July 31.
The FBI is now investigating.
That’s where the story becomes much more interesting.
Because Micro-Comm doesn’t simply sell office software.
It develops programmable logic controllers (PLCs) and SCADA technology used in wastewater facilities.
These systems interact with actual industrial equipment.
Pumps.
Valves.
Motors.
Sensors.
Treatment processes.
This is OT territory.
And OT doesn’t behave like an ordinary corporate network.
The Important Part: The Water Plants Were Not Hacked
Let’s kill the sensational headline before it starts.
There is currently no evidence that Barracuda used the Micro-Comm breach to take control of water treatment plants.
Micro-Comm says customer credentials and remote-access information for deployed equipment were not exposed.
The FBI also considers the Micro-Comm incident an opportunistic ransomware attack rather than part of the separate Iran-linked campaign that targeted water-sector PLCs during July.
That’s an important distinction.
Micro-Comm was compromised.
That does not mean:
“850,000 files leaked = 850,000 water systems compromised.”
Those are two completely different things.
So Why Is Everyone Paying Attention?
Because stolen documentation can be useful even when the systems themselves remain untouched.
Think about what an attacker can potentially learn from a manufacturer’s internal files.
Which products are deployed.
Which customers use them.
How systems are configured.
What network architecture is common.
Which versions exist.
Who operates them.
What equipment connects to what.
That’s reconnaissance.
And good reconnaissance can make the next attack much easier.
The Supply Chain Is the Weak Link
Imagine a municipal water utility with a heavily protected network.
Firewalls.
MFA.
Network segmentation.
Monitoring.
Incident response.
Then consider the company supplying part of its industrial infrastructure.
If that supplier gets compromised, attackers may gain information that the utility itself would never willingly expose.
That’s the supply-chain problem.
The attacker doesn’t necessarily need to break through the front door.
Sometimes they steal the blueprint from the company that built the door.
Researchers Found Interesting Files
An inventory of the leaked material reportedly includes references to government customers and at least one U.S. military facility, along with employee information and technical product documentation.
That doesn’t mean those organizations were compromised.
It means their association with Micro-Comm appears in the leaked material.
And that alone can be useful intelligence.
An attacker can correlate the information with Internet-facing systems and other publicly available data.
Suddenly a random IP address becomes:
“This municipality uses this specific industrial technology.”
That’s much more useful.
Internet-Exposed SCADA Is Still the Bigger Problem
Internet exposure remains one of the biggest risks for industrial control systems.
The FBI and EPA have already warned that attackers are targeting Internet-facing PLCs in the U.S. water and wastewater sector.
In several incidents, attackers changed PLC configurations, including IP addresses and passwords, causing operators to lose monitoring or control functionality.
That is a completely different level of compromise.
And it shows why the Micro-Comm leak matters.
You don’t want attackers getting both:
technical documentation
and
Internet-accessible industrial equipment.
That’s when reconnaissance can turn into exploitation.
Barracuda Says It’s Financially Motivated
Barracuda describes itself as a relatively new ransomware operation motivated by profit rather than government objectives.
That matters because the Micro-Comm breach should not automatically be connected to the separate Iranian-linked attacks against U.S. water infrastructure.
But criminals don’t need geopolitical motivations to create geopolitical consequences.
A ransomware gang can steal technical information for money.
Someone else can later find that information useful.
That’s the uncomfortable part of today’s cybercrime economy.
Data doesn’t care who stole it first.
Micro-Comm Says Customers Should Take Precautions
The company has advised customers to change passwords as a precaution.
That’s sensible even if customer credentials were not part of the stolen material.
If a supplier is compromised, assume the information surrounding authentication and access deserves another look.
Especially when industrial systems are involved.
The basic rule should be:
Don’t wait for proof that the credential was stolen.
If rotating it is cheap, rotate it.
The Water Sector Already Has a Problem
The Micro-Comm breach arrived during a period of increased attacks against U.S. water infrastructure.
The FBI and EPA warned in July that attackers were targeting Internet-facing PLCs and causing operational disruptions at water and wastewater facilities in multiple states.
Those attacks included cases where operators lost visibility or control over equipment.
So even though Micro-Comm appears to be a separate incident, the timing makes the breach much more uncomfortable.
The sector is already under pressure.
Now one of the companies supplying its technology has had hundreds of thousands of internal files exposed.
Bugstoday Opinion
This is exactly why supply-chain security keeps coming back.
Everyone wants to protect the water plant.
Everyone checks the firewall.
Everyone talks about segmentation.
Then someone compromises the company that supplies the PLC.
And suddenly the attacker potentially has a completely different view of the infrastructure.
The most worrying part isn’t the 644 GB.
It’s what’s inside.
A stolen database can be reset.
A password can be changed.
A credit card can be replaced.
But detailed documentation describing industrial systems can remain useful to an attacker for years.
And there is one more thing worth remembering:
this was reportedly a financially motivated ransomware attack, not a sophisticated nation-state operation.
That’s arguably worse in one respect.
It means you don’t necessarily need a geopolitical superpower to get close to critical infrastructure.
Sometimes all you need is a ransomware crew that finds the right supplier.
Bugstoday verdict: Micro-Comm’s water systems weren’t shown to be compromised, but the company’s data was. That’s enough to create a new reconnaissance problem for the utilities and infrastructure operators connected to it. The next attack doesn’t have to start at the water plant — it can start with a PDF, a system diagram or a leaked customer list stolen from the supplier.




