The FBI is investigating a previously unreported cyberattack on Micro-Comm, a Kansas company that makes programmable logic controllers (PLCs) used by wastewater facilities. Micro-Comm discovered the breach on July 31, and the Barracuda ransomware group subsequently published what it claimed were nearly 850,000 stolen files totaling roughly 644 GB of data.
What makes this incident different from the recent attacks on individual water utilities is that the hackers compromised a supplier of the technology used to operate water infrastructure. A list of the stolen files reportedly references specific government customers, including local governments and a U.S. military facility, as well as employee information and product diagrams. Roughly 200 Micro-Comm SCADAview CSX systems currently in use across the U.S. are accessible from the internet.
Micro-Comm said passwords, customer credentials and information enabling remote access to its devices were not exposed, and there is no evidence that the breach resulted in the operational compromise of a water system. The FBI also told the company that the attack appeared opportunistic and separate from the recent campaign targeting water utilities in at least seven states.
Donald McFarlane, Advisory Board Member, Xcape, Inc.
“The Micro-Comm incident may well have been an opportunistic ransomware/data-theft attack which is unconnected to the other recent attacks on OT. Nevertheless, that does not make the information stolen from it unimportant.
“An attack on one utility gives you one victim. An attack on a control-system supplier can potentially give you a map to hundreds of victims. Customer identities, engineering information, product diagrams and other technical data can significantly reduce the reconnaissance burden for somebody who wants to attack those systems later.
“Moreover, AI changes the economics of exploiting a large data dump. An adversary can use AI to help sift through the information, correlate customers with products and configurations, analyze engineering documentation, and if source code or other implementation details are available, look for product vulnerabilities worth exploiting. This matters all the more when roughly two hundred Micro-Comm systems are already reachable from the internet.
“You don’t need to steal the remote-access password for stolen engineering information to have intelligence value.
“Micro-Comm isn’t Siemens, Schneider or Rockwell. Despite manufacturing their own line of PLCs, it is a much smaller specialist manufacturer whose scale is closer to that of many regional control-system integrators than to the major global automation vendors.
“And that raises a broader concern: if we’re anticipating targeted adversarial activity rather than simply reacting to opportunistic ransomware, the integrator community deserves particular attention. The system integrators are often small regional engineering companies, but they may hold PLC programs, network diagrams, customer configurations and remote-access pathways for dozens of critical-infrastructure operators. From an adversary’s perspective, that’s an extraordinarily valuable concentration of information.
“The company maintaining the keys and blueprints to a few hundred water systems may have fifty employees. That doesn’t make it a small target.”
Denis Calderone, CTO, Suzu Labs:
“The ICS threat landscape is getting much more sophisticated. In 2023, CyberAv3ngers were simply changing default passwords on Unitronics PLCs and putting political messages on HMI screens. But by July of this year, CISA confirmed that actors were exfiltrating PLC project files using the vendors’ own engineering software and modifying Add-On Instructions to disable safety shutdowns while leaving the operator displays looking normal. Last week, five federal agencies warned that attackers are now using AI to generate working exploitation scripts against Siemens S7 controllers, calling it an evolution that ‘dramatically reduces the technical expertise and time required.’ That’s the trajectory, and the Micro-Comm breach feeds into that narrative.
“What makes the Micro-Comm breach so dangerous is the stolen proprietary data. The five-agency advisory said threat actors are collecting public information about PLC vulnerabilities and using AI to generate scripts that act on it. Now, imagine what becomes possible with a non-public disclosure? There are product diagrams, system architecture documents, customer-specific configurations, details about how SCADAview CSX communicates with the controllers it monitors. You hand that documentation to an unguardrailed AI model and the output is not generic Modbus reads on port 502, it’s targeted tooling built against a specific vendor’s implementation, informed by the manufacturer’s own engineering materials. That’s the difference between FrostyGoop’s 300 lines of Go sending blind register writes and something purpose-built to manipulate the logic in a specific way that an operator won’t notice.
“The FBI says this was opportunistic ransomware, and the attackers probably didn’t know what they had. Barracuda is selling it for $30,000. But there are roughly 200 SCADAview CSX systems sitting on the public internet right now according to Censys, and the buyers of this data may have very different intent than the people who stole it. The joint advisory (AA26-231A) pointed out that the Siemens attack had pre-positioning as one of its goals, so utilities running Micro-Comm equipment should be getting those systems off the internet today, rotating every credential, and asking their integrator to verify that PLC project files match a known-good baseline. If you rely on this vendor’s products, you need to stay diligent. The window between when this data hit the market and when someone with real capability decides to use it is the only time you have to close the gap.”
Critical infrastructure needs to be protected. Or hacks like this will be commonplace. That is as commonplace as every other hack that currently exists. Which is a really sad state of affairs.

The FBI created its own crypto token to catch a $7.5 billion pump-and-dump fraud ring
Posted in Commentary with tags FBI on August 26, 2026 by itnerdA UK judge rejected Manpreet Kohli’s fight against extradition to the US on wire fraud and market manipulation charges tied to Saitama, an Ethereum-based token he led that peaked at a $7.5 billion market value, with prosecutors alleging he and more than a dozen co-conspirators publicly claimed to be holding and buying the token while privately selling their own holdings for millions in profit. The case marks the first known instance of the FBI creating its own digital token specifically to investigate this kind of fraud, and Kohli’s case now goes to UK ministers to decide on extradition, with Kohli free on £200,000 bail and able to appeal.
More details here: Cryptocurrency chief facing extradition from UK to US on fraud charges – Yahoo News Canada
Jason Brown, Director of Counter Fraud Operations, iCOUNTER:
“A token does not reach a $7.5 billion valuation in isolation. The activity moved through market makers, exchanges, wallets, and counterparties. That is the third-party problem in one sentence, and it is why detection has to start outside your perimeter.
What’s notable in this case is how the FBI worked the whole ecosystem, not just the issuer. Prosecutors say Kohli and his co-conspirators publicly claimed to be holding and buying Saitama tokens while privately selling their own holdings for millions in profit. Kohli alone is alleged to have made around $20 million. That’s a classic pump-and-dump dressed up in crypto terminology. But the same investigation went after the market makers hired to manufacture the volume, and to reach them the FBI stood up its own token, NexFundAI, and watched firms like ZM Quant and CLS Global manipulate it in real time. Trading was disabled before retail investors were exposed. The issuer and the vendors were two halves of one campaign, and neither half was visible from inside a single platform.
That’s the lesson for anyone running fraud detection today, in crypto or otherwise. The Saitama token itself was never the crime scene. The crime happened in the gap between what was said publicly and what was done privately across wallets and counterparties, and you only see that gap if you’re watching the full network, not just the asset. A $7.5 billion valuation built on that kind of coordinated deception should be a wake-up call for anyone who thinks perimeter-level monitoring of a single platform or exchange is sufficient. It isn’t. The fraud is distributed by design, and the detection has to be too.”
Fact: Every one of these people need to be extradited to face the legal system (such as it is in the US). That is the only way that bad guys will stop doing bad things.
Leave a comment »