What happened
Micro-Comm said it discovered the breach on July 31, 2026. Barracuda posted on August 6, 2026 what it claimed were nearly 850,000 files totalling roughly 644 gigabytes. Micro-Comm told customers on August 8, 2026 that it had experienced a limited malware attack. Reuters first publicly reported the incident on August 26, 2026 and said the FBI was in contact with the company. Micro-Comm said customer passwords and credentials are stored by customers and were not present in the released files, and it said remote-access information for its devices was not included.
Reuters reported that roughly 200 SCADAview CSX systems in the United States were internet-accessible, citing Censys. An index of the posted files referenced government customers, employee names and product diagrams, but publication of an index does not establish compromise of a customer water system. The FBI and EPA alert for the separate water-PLC activity names Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series and says actors changed IP addresses and passwords, causing loss of monitoring and control. Attribution posture: Barracuda claimed the Micro-Comm incident, but neither the company nor the FBI publicly validated that claim or linked it to the contemporaneous water-PLC campaign. The cited source did not publish the specific indicators described as Incident indicators and downstream victims.
Why this matters now
The enterprise consequence is not that 200 water systems were shown to be compromised; the evidence does not support that conclusion. The risk is that a technology supplier’s files, customer references and product diagrams may lower future reconnaissance costs while a reported population of SCADAview CSX deployments remains internet-accessible. Water operators must determine whether their own deployment, credentials, diagrams or support relationships were represented rather than treating the incident as either harmless or a sector-wide breach.
This is a third-party assurance decision with operational-technology consequences. Supplier statements that passwords or remote-access information were absent are relevant but do not close customer-specific questions about architectural detail, support access, exposed management surfaces or reused credentials. The contemporaneous attacks against internet-facing water PLCs demonstrate why reachability and credential governance matter, but Micro-Comm and the FBI said this incident was separate. Leaders should preserve that distinction while acting on the shared control weakness.
The decision for security leaders
Water and wastewater operators should open a supplier-assurance action rather than assume direct compromise. Ask Micro-Comm to identify customer-specific records, product diagrams, support information, access methods and data categories associated with the organisation. Require clear separation between facts established by forensics, the Barracuda claim and precautionary recommendations. Procurement or vendor-risk teams should track limitations in the supplier’s answer rather than treating silence as assurance.
Engineering and security teams should independently verify actual internet reachability, management protocols, credential uniqueness and support paths for SCADAview CSX and related control systems. If supplier files contain accurate diagrams or customer names, update threat models and monitoring priorities. Any direct exposure should be removed or placed behind a controlled gateway, with access restricted to authorised sources and recorded for investigation.
Evidence of closure
- Supplier assurance records the incident scope, data categories, access path and customer-impact determination.
- External scans confirm no unauthorised internet exposure of SCADAview CSX management interfaces.
- Credential attestations confirm unique passwords and completed rotation for affected integrations.
- Engineering review documents whether exposed diagrams alter threat models or segmentation controls.
The Security.io assessment
The newly public confirmation changes an older incident into a current customer-assurance decision. The breach and file posting are credible enough to require action, but the public evidence does not establish that Micro-Comm customer credentials, remote-access secrets or downstream water systems were compromised. Treating the event as a confirmed operational-technology breach would exceed the sources and could misdirect response resources.
No malware hash, ransom note, exploited vulnerability, customer device credential or confirmed downstream victim was published in the cited sources. The strongest response is consequently customer-specific validation: identify products and support relationships, test public exposure, examine supplier information relevant to the organisation and document what remains unknown. The separate FBI and EPA warning provides urgency around internet-facing PLCs, but it must not be used as attribution evidence for Micro-Comm.
Questions for the morning meeting
- Do we use Micro-Comm products or receive support through its environment?
- Are any SCADAview CSX management interfaces reachable from the public internet?
- Could posted diagrams or customer references materially improve reconnaissance against our facilities?
- What supplier evidence would distinguish corporate-file theft from downstream operational access?