Iran-linked hacking group Handala claimed it breached California Water Service (Cal Water), a major utility serving roughly two million people across about 100 California communities, and released a 5 GB data dump that reportedly included customer billing records, personally identifiable information, administrative credentials, and network infrastructure details tied to multiple service districts. Reporting indicates the intrusion may have begun through an internal RTKBase GPS correction system used by field crews, with stolen passwords potentially enabling lateral movement into the customer billing environment.
Security researchers and incident reporting said the available evidence supports compromise of a GPS-related server and billing database, but does not confirm disruption of operational technology, industrial control systems, or water treatment operations, despite Handala's claims that it could shut off water supplies. Experts described the incident as consistent with the group's pattern of combining real intrusions and data theft with exaggerated claims, while warning that the breach underscores the need for password resets and stronger segmentation between operational, IoT, and corporate networks amid broader concerns about Iranian targeting of U.S. critical infrastructure.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
After learning of Handala's breach claim last Thursday, California Water Service activated its cybersecurity response plan and began working with state and federal partners and external experts. The utility said preliminary findings showed no known operational disruptions to its water, wastewater, or billing systems.
SC Media said the Cal Water incident followed Handala's wiper attack on Stryker in March 2026, identifying an earlier campaign activity by the same Iran-linked group.
On 2026-06-11, Handala claimed it had breached California Water Service and released about five gigabytes of data. Reported material included customer billing information, administrative credentials, and network-related information tied to multiple service districts and an internal GPS correction environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcesecuritymagazine.com
Open sourcehackread.com
Open sourcescworld.com
Open sourcedataminr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.