Iran-linked hackers calling themselves Handala say they broke into California Water Service and published 5GB of stolen data. The leak reportedly includes customer personal information, billing records, administrative credentials for Cal Water's RTKBase GNSS base-station platform, and an NTRIP source password; Dataminr assesses the RTKBase instance was likely the initial access point or lateral-movement path into a separate billing environment, though confirmed disruption of industrial control systems has not been reported.
Why it matters: A water utility serving about 2 million customers may have exposed sensitive customer data, and the presence of infrastructure credentials raises concern about follow-on intrusion or disruption. Cal Water and any connected operators should rotate exposed credentials immediately, audit RTKBase and billing access, and review segmentation and logs for further compromise.
Eduard Kovacs
2026.06.25
96% relevant
This directly updates the same Cal Water/Handala incident with Mandiant’s investigation results, saying the activity was limited to a small number of accounts in two third-party platforms and that no evidence was found of threat actor activity in Cal Water’s internal IT or OT environments.
Eduard Kovacs
2026.06.16
96% relevant
This article updates the same Handala-Cal Water incident with the company's first public response, saying it activated its incident response plan, is coordinating with state and federal partners, and has found no known operational disruption so far despite the leaked data claims.
Ionut Arghire
2026.06.12
100% relevant
This article appears to be the first concrete report in the set about Handala's claimed intrusion into Cal Water, including the alleged victim, leaked data types, and suspected access path.
← Back to all stories