The Tehran-linked hacking group Handala breached California Water Service, leaking 5GB of sensitive customer data and administrative credentials after exploiting a poorly secured GPS tool used by field crews.
Key Points
- Hackers accessed a customer billing database and an internal RTKBase GPS platform used across seven California water districts.
- The exposed data includes names, addresses, phone numbers, account numbers, and payment histories for residential and commercial customers.
- Attackers gained entry through an open-source GPS interface accessible via standard HTTP port 10000 on lightweight, poorly secured hardware.
- Plaintext administrative credentials for seven districts were published online, potentially compromising the utility's broader network infrastructure.
- Cybersecurity firm Dataminr warns that Handala’s history of deploying destructive wipers suggests this data theft could precede future operational disruptions.