The Iran-linked threat group Handala compromised California Water Service on June 11, 2026, exposing customer billing data and internal GPS infrastructure used for maintaining critical water utility systems.
Key Points
- Handala published a 5GB data dump containing customer names, addresses, phone numbers, and payment histories from multiple California Water Service districts.
- The breach originated through an internet-exposed RTKBase GNSS platform, which served as a lateral pivot point to access the company's billing database.
- Exposed infrastructure includes seven operational districts, such as Bakersfield, Chico, Salinas, Stockton, and Visalia, with plaintext administrative credentials now publicly available.
- While no disruption to water treatment or SCADA systems occurred, the group is known for using destructive wipers and MBR-overwriting tools in previous attacks.
- Security experts advise utilities to immediately audit internet-facing GPS hardware and enforce strict network segmentation between operational technology and administrative billing environments.