Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iran-Linked Group Claims Cal Water Cyber Breach

Iran-Linked Group Claims Cal Water Cyber Breach

Posted on June 13, 2026 By CWS

An Iranian-affiliated cyber group, known as Handala, has recently claimed responsibility for breaching the security of California Water Service (Cal Water). The group reportedly released 5 gigabytes of data allegedly obtained from the US water utility, in what they describe as a response to the US’s recent activities in Iran.

Details of the Cyber Intrusion

The hacking group publicized their actions on their blog, stating that while they had the potential to disrupt water services, they opted against it. Intelligence firm Dataminr suggests that Handala may have infiltrated Cal Water’s RTKBase, a GNSS base station platform, potentially using it as a springboard to access the billing system.

Cal Water ranks among the most significant investor-owned water utilities in the nation, serving approximately two million individuals across 100 California communities. Dataminr has confirmed that the Chico District of Cal Water was specifically targeted in this attack, with leaked data indicating access to customer billing information and the internal RTKBase application.

Implications of the Data Breach

The breach resulted in the exposure of personally identifiable information (PII), including names, addresses, phone numbers, account numbers, and payment histories. Additionally, administrative credentials for the RTKBase platform and NTRIP source passwords were compromised. The hackers also enumerated IP addresses connected to Cal Water’s NTRIP network across seven districts.

Although no operational technology (OT) or industrial control system (ICS) disruption has been confirmed, Dataminr warns that Handala’s toolkit includes custom wipers and MBR-overwriting capabilities. This indicates a potential for destructive actions, similar to previous incidents involving the group.

Recommended Security Measures

In response to the breach, it is critical to treat all exposed credentials as compromised and rotate them immediately. The RTKBase instance should be taken offline and thoroughly audited, while network segmentation and billing system access logs must be reviewed.

Cal Water has not yet made a public statement regarding the breach. SecurityWeek has reached out for a comment and will update with any responses.

Background on Handala

Handala has been active since at least 2008 and is associated with Iran’s Ministry of Intelligence and Security (MOIS). The group, also known by names such as Banished Kitten and Red Sandstorm, engages in activities ranging from hacktivism to data exfiltration and destructive attacks.

Dataminr suggests that Handala’s operational pattern typically involves initial claims followed by escalated actions. Security teams should consider the potential for further destructive activities and adjust their postures accordingly.

Security Week News Tags:Cal Water hack, cyber attack, Cybersecurity, data breach, Handala, infrastructure security, Iranian hackers, PII leak, Threat Actors, US utilities

Post navigation

Previous Post: Chinese Hackers Exploit Linux Login Systems for Years
Next Post: OnyxC2 Malware Exploits 210 Apps to Steal Credentials

Related Posts

750,000 Impacted by Data Breach at The Alcohol & Drug Testing Service 750,000 Impacted by Data Breach at The Alcohol & Drug Testing Service Security Week News
China Accuses US of Cyberattack on National Time Center China Accuses US of Cyberattack on National Time Center Security Week News
From Young Hacker to CEO: The Journey of Ben Harris From Young Hacker to CEO: The Journey of Ben Harris Security Week News
Cisco Warns of Hardcoded Credentials in Enterprise Software Cisco Warns of Hardcoded Credentials in Enterprise Software Security Week News
Insights from Sophos CISO Ross McKerchar Insights from Sophos CISO Ross McKerchar Security Week News
Impostor Uses AI to Impersonate Rubio and Contact Foreign and US Officials Impostor Uses AI to Impersonate Rubio and Contact Foreign and US Officials Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark