logo

Iran-Linked Handala Breached a California Water Utility. It Could Have Done Worse, and It Knows That.

ID: c41394ed-40ec-502c-bb91-5991e26e01bb

STIX ID: report--c41394ed-40ec-502c-bb91-5991e26e01bb

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-06-12

Date Updated: 2026-06-13

Author: Pierluigi Paganini

...
...

On June 11, 2026, Iran-linked threat group Handala claimed a breach of California Water Service (Cal Water) and published a 5GB proof-of-concept dump containing customer billing PII (names, addresses, phone numbers, account numbers, payment histories) and exposed RTKBase NTRIP/GNSS credentials. Dataminr analysis indicates Handala accessed both an RTKBase GNSS caster (used by field crews across seven districts) and a customer billing database, using the internet-exposed RTKBase management interface as a probable initial access vector; no OT/SCADA disruption is confirmed, but the actor has known destructive wipers and could escalate to destructive operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.