Serves approximately 2 million customers
A pro-Iranian hacktivist group calling itself Handala has claimed responsibility for a cyberattack targeting the California Water Service (Cal Water), one of the largest water utilities in the United States. In a statement on June 12, 2026, the group positioned the attack as retaliation for alleged U.S. actions against civilian water infrastructure in Iran. Handala stated it deliberately refrained from disrupting water services, intending the breach as a warning. To validate their claim, the group leaked 5GB of data allegedly stolen from Cal Water. The data reportedly includes customer personally identifiable information (PII) and administrative credentials for a GPS network, suggesting a successful intrusion into the utility's peripheral or administrative systems.
Details on the initial access vector are not fully confirmed, but the leaked data points to the compromise of an RTKBase NTRIP GPS correction network as a probable entry point. These networks are used for high-precision location services, often in surveying and infrastructure management. Compromising this system likely provided the credentials and access needed to pivot to other systems, such as the customer billing database.
Screenshots released by Handala show access to a network management interface with visibility into multiple Cal Water districts, including Bakersfield, Chico, Salinas, and Stockton. This suggests the attackers gained a significant foothold with broad administrative access, at least within the compromised system.
T1190 - Exploit Public-Facing Application: The likely initial access vector was an internet-exposed, vulnerable component of the RTKBase network or another peripheral system.T1078 - Valid Accounts: After the initial breach, the attackers used stolen administrative credentials to access and navigate the network management interface.T1005 - Data from Local System: The group collected customer PII from a billing system or connected database.T1530 - Data from Cloud Storage Object: If the billing data was stored in a cloud environment, this technique would apply.T1567 - Exfiltration Over Web Service: The attackers exfiltrated 5GB of data to their own servers before leaking it.While Handala claims it did not impact water operations, the incident is still highly significant:
No specific Indicators of Compromise (IPs, domains, hashes) were provided in the source articles.
Security teams at critical infrastructure organizations should hunt for the following patterns:
url_pattern*/rtkbase/* or */ntrip/*log_sourcenetwork_traffic_patternaccount_activityCal Water confirms breach limited to IT systems, no impact on water production or industrial control systems.
California Water Service (Cal Water) and independent analysis by Dataminr have confirmed that the Handala cyberattack was limited to non-critical IT systems, including a GPS server and customer billing database. Crucially, there was no impact on water production, delivery, or industrial control systems (ICS). This clarification significantly reduces the perceived operational severity of the incident, highlighting the effectiveness of network segmentation in containing the breach. The attack's primary goal appears to be propaganda and psychological warfare rather than kinetic damage.
Handala announces its cyberattack on California water infrastructure and leaks 5GB of data.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.