Iran-Linked Handala Breached a California Water Utility. It Could Have Done Worse, and It Knows That.
ID: c41394ed-40ec-502c-bb91-5991e26e01bb
STIX ID: report--c41394ed-40ec-502c-bb91-5991e26e01bb
Feed Name: Security Affairs
On June 11, 2026, Iran-linked threat group Handala claimed a breach of California Water Service (Cal Water) and published a 5GB proof-of-concept dump containing customer billing PII (names, addresses, phone numbers, account numbers, payment histories) and exposed RTKBase NTRIP/GNSS credentials. Dataminr analysis indicates Handala accessed both an RTKBase GNSS caster (used by field crews across seven districts) and a customer billing database, using the internet-exposed RTKBase management interface as a probable initial access vector; no OT/SCADA disruption is confirmed, but the actor has known destructive wipers and could escalate to destructive operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
