By Gregory Hale
Olathe, Kansas-based maker of programmable logic controllers (PLCs), Micro-Comm, suffered a ransomware attack in late July where the attacker claimed to steal 644 GB of data.
Micro-Comm supplies control technology to water and wastewater utilities and the ransomware group Barracuda said it stole 644 GB of data from 850,000 files. To that end, Micro-Comm said sensitive user credentials and remote-access information did not end up compromised.
In this attack, the FBI said it is investigating the ransomware attack of the supplier of PLCs and related technology used by public water and wastewater facilities. The exposed material reportedly includes government customer names and system diagrams, information that could assist later attacks even where operating credentials did not end up compromised.
New Threat Group
Barracuda, a relatively new ransomware group that describes itself as financially motivated rather than government sponsored, claimed responsibility. On Aug. 6, Barracuda posted nearly 850,000 Micro-Comm files.
In an Aug. 8 customer newsletter, Micro-Comm described the event as a limited malware attack and said sensitive material within the affected files ended up encrypted.
A spokesperson for the FBI’s Kansas City field office confirmed the bureau was in contact with Micro-Comm and coordinating with other law enforcement agencies. The company co-owner said the FBI characterized the breach as opportunistic rather than an operation that specifically selected Micro-Comm.
No further information was immediately available on the attack and what the attackers were seeking in terms of a ransom.
For more information on other incidents in the industry click on ICSSTRIVE.com.

