Hack of water sector supplier draws FBI scrutiny as Iran-linked cyber concerns grow

U.S.authorities are investigating a data breach at a small maker of water utility technology, highlighting infrastructure cybersecurity threats even though the Kansas firm was apparently not part of a suspected Iranian-affiliated campaign against water plants in Minnesota and other states starting in July.The company and the FBI confirmed the attack at Micro-Comm in Olathe, Kansas, which has not previously been reported.
Responsibility was claimed by Barracuda, a relatively new ransomware group that says it is motivated by profit and is not government sponsored.The group posted on August 6 what it said was nearly 850,000 company files with roughly 644 gigabytes of data.Micro-Comm makes programmable logic controllers (PLCs), computer devices used to control machinery within critical infrastructure networks, in this case by wastewater processing facilities.The Micro-Comm breach highlighted the complexity of securing local U.S.
water systems and the vendors that support them from increasing cyberattacks on computer systems embedded in the nation’s critical infrastructure.The breach occurred during a late July spate of hacks that targeted PLCs in Minnesota and at least six other states.Cybersecurity experts believe the attacks were part of a long-running Iranian-affiliated cyber campaign.The FBI and the Cybersecurity and Infrastructure Security Agency warned July 30 that hackers were targeting PLCs from U.S.-based Rockwell Automation (ROK.N), France’s Schneider Electric (SCHN.PA), and Germany’s Siemens (SIEGn.DE).CISA said August 19 that hackers were using AI to ease their attacks on Siemens equipment.
The company subsequently said it was working with CISA and its products are safe.Dixon Land, a spokesperson for the FBI’s Kansas City field office, said in an email that the FBI was in contact with Micro-Comm about the hack and coordinating with other law enforcement agencies.CISA referred questions to Micro-Comm.Jim Co...