AUTO-UPDATED

100 days after the Iran war started — Tehran-backed group breaches California Water Service but claims they 'chose not to disrupt water access'

The Tehran-linked hacking group Handala breached California Water Service, leaking 5GB of sensitive customer data and administrative credentials after exploiting a poorly secured GPS tool used by field crews.

Key Points

  • Hackers accessed a customer billing database and an internal RTKBase GPS platform used across seven California water districts.
  • The exposed data includes names, addresses, phone numbers, account numbers, and payment histories for residential and commercial customers.
  • Attackers gained entry through an open-source GPS interface accessible via standard HTTP port 10000 on lightweight, poorly secured hardware.
  • Plaintext administrative credentials for seven districts were published online, potentially compromising the utility's broader network infrastructure.
  • Cybersecurity firm Dataminr warns that Handala’s history of deploying destructive wipers suggests this data theft could precede future operational disruptions.

Why it Matters

This breach highlights critical vulnerabilities in the operational technology used by essential US utility providers, moving the threat from theoretical to active. The exposure of customer data and network credentials creates immediate risks for both individual privacy and the long-term security of regional water infrastructure.
TechRadar Published by Efosa Udinmwen
Read original