California Water Service said an investigation into intrusion claims by the Iranian-linked group Handala found no evidence of attacker activity in its internal IT or operational technology environments, despite the group’s assertion that it could disrupt the water supply. Cal Water, working with Mandiant and government partners, said the incident was limited to unauthorized access to a small number of user accounts in two third-party service provider platforms, one active customer online account accessed with stolen credentials, and a third-party GPS correction website that held no sensitive information. The company said the customer portal access did not expose payment data or provide a path into its billing system, and investigators found no indication that industrial control systems were accessed.
The case adds to scrutiny of Handala, which has been linked by researchers and officials to Iranian operations targeting critical infrastructure and private-sector organizations. Analysts reviewing files the group claimed to leak from Cal Water found personal information and signs that a customer billing system and an internal application may have been compromised, even as the utility maintained that core internal and OT systems showed no evidence of intrusion. In a separate matter, medical device maker Stryker is seeking dismissal of a class action tied to a March cyberattack also claimed by Handala, arguing there is no evidence the plaintiffs’ personal data was accessed, underscoring a broader pattern in which the group pairs disruptive claims and alleged data theft with contested evidence of actual compromise.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Cal Water said its investigation found unauthorized access was limited to a small number of user accounts in two third-party service provider platforms, one active customer online account accessed with stolen credentials, and an external GPS correction website. The company and Mandiant said they found no evidence of threat actor activity in Cal Water's internal IT or operational technology environments.
Stryker sought dismissal of a proposed class action lawsuit brought by current and former employees, arguing its investigation found no evidence that the named plaintiffs' personally identifiable information was accessed. The lawsuit followed the company's March 2026 cyberattack and raised questions about standing where disruption is evident but plaintiff data theft is unproven.
After allegations surfaced on June 11, 2026, Cal Water activated its cybersecurity response plan and worked with Mandiant and government partners to investigate the claimed intrusion. The investigation focused on whether the Iranian-linked group Handala had accessed internal IT or operational technology systems.
In March 2026, Handala claimed responsibility for a cyberattack on Stryker, alleging it stole 50 terabytes of data and wiped 200,000 devices and 12 petabytes of Stryker data. Stryker said the incident disrupted internal electronic ordering and related client-facing systems for several weeks, but not devices and systems connected to customers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcesecuritymagazine.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.