FBI Investigates Cyberattack on Kansas Water Technology Firm

 

The FBI is investigating a cyberattack targeting Micro-Comm, a Kansas-based company that develops technology used by water and wastewater utilities, adding to concerns over the security of America’s critical water infrastructure.
The incident at the Olathe, Kansas, company was confirmed by both Micro-Comm and the FBI. It does not appear to be connected to a suspected Iran-linked cyber campaign that targeted water facilities in Minnesota and several other U.S. states beginning in July. However, the breach underscores the broader cybersecurity risks facing water systems and the technology providers that support them.
A ransomware operation known as Barracuda, which describes itself as financially motivated and independent of government sponsorship, claimed responsibility for the attack. On August 6, the group released what it said were nearly 850,000 company files, totaling about 644 gigabytes of data.
Micro-Comm produces programmable logic controllers (PLCs), computerized systems that help control machinery used in critical infrastructure, including wastewater treatment facilities.
The attack came as U.S. authorities were already dealing with a series of intrusions targeting PLCs in Minnesota and at least six other states in late July. Cybersecurity specialists have linked those incidents to an ongoing campaign allegedly associated with Iran.
On July 30, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) warned that cybercriminals were actively targeting PLCs manufactured by U.S.-based Rockwell Automation, France’s Schneider Electric and Germany’s Siemens.
CISA later reported on August 19 that attackers were using artificial intelligence to make attacks against Siemens systems more efficient. Siemens said it was working with CISA and maintained that its products remain secure.
Dixon Land, a spokesperson for the FBI’s Kansas City field office, said in an email that the bureau was in communication with Micro-Comm and working alongside other law enforcement agencies. CISA directed questions about the incident to Micro-Comm.
Jim Cote, a co-owner of Micro-Comm, said the company detected the intrusion on July 31. According to Cote, the information released by the attackers did not contain sensitive data such as customer passwords or credentials, which are retained by individual clients. He also said the exposed material did not include information about Micro-Comm’s ability to remotely access its equipment.
In a client newsletter dated August 8, Micro-Comm described the incident as a limited malware attack and said sensitive information within the affected files had been encrypted. The company stated that the incident was "in no way related to water system hacks currently being reported on the news."
Cote said the FBI informed the company that the attack appeared to be opportunistic rather than a targeted operation against Micro-Comm. Despite that assessment, the company recommended that customers change their passwords as a precaution.
Data from internet-monitoring platform Censys indicates that around 200 deployments of Micro-Comm’s SCADAview CSX systems in the U.S. remain accessible online. Meanwhile, an index maintained by cybercrime research platform eCrime.ch reportedly contains references to public-sector customers, including municipalities and a U.S. military facility, as well as employee names and technical information such as system diagrams.
Tom Hegel, a senior threat researcher at cybersecurity company SentinelOne, said the leaked information does not suggest that any water facility experienced an operational shutdown. However, he warned that the information could potentially provide useful intelligence to malicious actors in the future.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: