水务行业供应商遭黑客攻击引发FBI调查,与伊朗相关的网络安全担忧加剧


2026-08-26T10:02:31.556Z / 路透社

一名行人途经美国联邦调查局总部墙上的FBI徽章,此前特朗普政府对司法部启动大规模裁员举措数日。摄于美国华盛顿,2025年2月3日。路透社/凯文·拉马克 购买授权许可,将在新标签页打开

  • 概要
  • 企业
  • 梭鱼团伙称已发布近85万个Micro-Comm公司文件
  • Micro-Comm于7月31日发现遭攻击
  • 公司称未获取敏感信息

8月26日(路透社)——美国当局正在调查一家小型水务公用技术制造商的数据泄露事件,凸显了基础设施网络安全威胁,尽管这家位于堪萨斯州的公司显然并未卷入7月以来针对明尼苏达州及其他州水厂的疑似伊朗关联黑客活动。

该公司与美国联邦调查局(FBI)证实了位于堪萨斯州奥拉西的Micro-Comm公司遭遇攻击,此事此前未被报道。一个相对新兴的勒索软件组织“梭鱼团伙”宣称对此负责,该组织称其动机是牟利,并非受政府指使。

路透社每日简报通讯为您提供开启一天所需的全部新闻。点击此处订阅。

该团伙于8月6日发布了其声称的近85万个公司文件,数据量约644吉字节。Micro-Comm公司生产可编程逻辑控制器(PLC),这是一种用于控制关键基础设施网络内机械设备的计算机设备,本次涉及的是污水处理厂的相关设备。

此次Micro-Comm数据泄露事件凸显了保障美国地方水务系统及其支持供应商的复杂性,当前针对美国关键基础设施中嵌入式计算机系统的网络攻击日益增多。

此次泄露事件发生在7月下旬针对明尼苏达州及至少其他六个州的PLC设备的一系列黑客攻击期间。网络安全专家认为,这些攻击属于一场长期的、与伊朗有关联的网络活动。

美国联邦调查局与网络安全与基础设施安全局(CISA)
曾发布警告,将在新标签页打开
7月30日称,黑客正针对美国罗克韦尔自动化公司
(ROK.N),将在新标签页打开
、法国施耐德电气
(SCHN.PA),将在新标签页打开
以及德国西门子
(SIEGn.DE),将在新标签页打开
的PLC设备发动攻击。

美国网络安全与基础设施安全局8月19日称,黑客正利用人工智能简化针对西门子设备的攻击。该公司随后表示,正与CISA合作,其产品是安全的。

美国联邦调查局堪萨斯城分局发言人迪克逊·兰德在一封电子邮件中表示,FBI已就此次黑客攻击与Micro-Comm公司取得联系,并正与其他执法机构协调行动。CISA则将相关问题转介给Micro-Comm公司。

该公司联合所有者吉姆·科特在采访中表示,公司于7月31日发现遭入侵。

科特称,黑客发布的文件未包含用户密码和凭证等敏感信息,这类信息由客户存储,也未涉及Micro-Comm远程访问其设备的相关数据。

该公司在8月8日的通讯中告知客户,其遭遇了一起有限的恶意软件攻击,文件中的任何敏感信息均已加密。公司称此次泄露“与新闻中当前报道的水务系统黑客攻击毫无关联”。

科特表示,FBI告知该公司,此次数据泄露是一次机会主义攻击,并非专门针对Micro-Comm公司,公司出于谨慎建议客户更改密码。

根据互联网监测公司Censys的数据,该公司的一款产品SCADAview CSX系统中约有200台在美国各州使用的设备可通过互联网访问。

网络犯罪研究平台
eCrime.ch,将在新标签页打开
收集的文件列表提及了特定的政府客户,包括地方政府机构和一处美国军事设施、员工姓名以及产品信息如图纸等。

网络安全公司SentinelOne的高级威胁研究员汤姆·黑格尔表示,文件被公布并不意味着任何水务系统在运营上遭到破坏,但这些信息长期来看可能会帮助黑客。

由底特律的AJ·维森斯报道;克里斯·桑德斯与辛西娅·奥斯特曼编辑

我们的准则:路透社诚信准则。

Hack of water sector supplier draws FBI scrutiny as Iran-linked cyber concerns grow

2026-08-26T10:02:31.556Z / Reuters

A person passes by the FBI seal on the wall of the FBI headquarters, days after the Trump administration launched a sweeping round of cuts at the Justice Department, in Washington, U.S., February 3, 2025. REUTERS/Kevin Lamarque Purchase Licensing Rights, opens new tab

  • Summary
  • Companies
  • Barracuda says it posted nearly 850,000 Micro-Comm files
  • Micro-Comm discovered attack on July 31
  • Company says no sensitive information obtained

Aug 26 (Reuters) – U.S. authorities are investigating a data breach at a small maker of water utility technology, highlighting infrastructure cybersecurity threats even ​though the Kansas firm was apparently not part of a suspected Iranian-affiliated campaign against water plants in Minnesota ‌and other states starting in July.

The company and the FBI confirmed the attack at Micro-Comm in Olathe, Kansas, which has not previously been reported. Responsibility was claimed by Barracuda, a relatively new ransomware group that says it is motivated by profit and is not government sponsored.

The Reuters Daily Briefing newsletter provides all the news you need to start your day. Sign up here.

The group posted ​on August 6 what it said was nearly 850,000 company files with roughly 644 gigabytes of data. Micro-Comm makes programmable ​logic controllers (PLCs), computer devices used to control machinery within critical infrastructure networks, in this case by wastewater ⁠processing facilities.

The Micro-Comm breach highlighted the complexity of securing local U.S. water systems and the vendors that support them from increasing cyberattacks on ​computer systems embedded in the nation’s critical infrastructure.

The breach occurred during a late July spate of hacks that targeted PLCs in Minnesota and ​at least six other states. Cybersecurity experts believe the attacks were part of a long-running Iranian-affiliated cyber campaign.

The FBI and the Cybersecurity and Infrastructure Security Agency

warned, opens new tab
July 30 that hackers were targeting PLCs from U.S.-based Rockwell Automation

(ROK.N), opens new tab
, France’s Schneider Electric

(SCHN.PA), opens new tab
and Germany’s Siemens

(SIEGn.DE), opens new tab
.

CISA said August 19 that hackers were ​using AI to ease their attacks on Siemens equipment. The company subsequently said it was working with CISA and its products are safe.

Dixon Land, ​a spokesperson for the FBI’s Kansas City field office, said in an email that the FBI was in contact with Micro-Comm about the hack and ‌coordinating ⁠with other law enforcement agencies. CISA referred questions to Micro-Comm.

Jim Cote, a co-owner of the company, said in an interview that the company discovered the breach on July 31.

Cote said the files released by the hackers did not contain sensitive information such as user passwords and credentials, which are stored by the customer, or data related to Micro-Comm’s ability to remotely access its devices.

The company told customers in ​an August 8 newsletter that ​it experienced a limited malware ⁠attack and any sensitive information in the files was encrypted. The company said the breach was “in no way related to water system hacks currently being reported on the news.”

Cote said the FBI told ​the company that the data breach was an opportunistic attack not specifically targeted at Micro-Comm, ​and the company ⁠recommended customers change passwords out of an abundance of caution.

Roughly 200 of the company’s SCADAview CSX systems, one of the company’s products, in use in U.S. states are accessible from the internet, according to internet-monitoring firm Censys.

A list of files gathered by cybercrime research platform

eCrime.ch, opens new tab
refers ⁠to specific ​government customers, including localities and a U.S. military facility, employee names and product ​information such as diagrams.

Tom Hegel, a senior threat researcher at cybersecurity firm SentinelOne, said the release of files did not mean any water system was operationally compromised, ​but the information could help hackers in the long term.

Reporting by AJ Vicens in Detroit; Editing by Chris Sanders and Cynthia Osterman

Our Standards: The Thomson Reuters Trust Principles.

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

湘ICP备2026001899号-2