Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iran-Linked Group Claims Cal Water Cyber Breach

Iran-Linked Group Claims Cal Water Cyber Breach

Posted on June 13, 2026 By CWS

An Iranian-affiliated cyber group, known as Handala, has recently claimed responsibility for breaching the security of California Water Service (Cal Water). The group reportedly released 5 gigabytes of data allegedly obtained from the US water utility, in what they describe as a response to the US’s recent activities in Iran.

Details of the Cyber Intrusion

The hacking group publicized their actions on their blog, stating that while they had the potential to disrupt water services, they opted against it. Intelligence firm Dataminr suggests that Handala may have infiltrated Cal Water’s RTKBase, a GNSS base station platform, potentially using it as a springboard to access the billing system.

Cal Water ranks among the most significant investor-owned water utilities in the nation, serving approximately two million individuals across 100 California communities. Dataminr has confirmed that the Chico District of Cal Water was specifically targeted in this attack, with leaked data indicating access to customer billing information and the internal RTKBase application.

Implications of the Data Breach

The breach resulted in the exposure of personally identifiable information (PII), including names, addresses, phone numbers, account numbers, and payment histories. Additionally, administrative credentials for the RTKBase platform and NTRIP source passwords were compromised. The hackers also enumerated IP addresses connected to Cal Water’s NTRIP network across seven districts.

Although no operational technology (OT) or industrial control system (ICS) disruption has been confirmed, Dataminr warns that Handala’s toolkit includes custom wipers and MBR-overwriting capabilities. This indicates a potential for destructive actions, similar to previous incidents involving the group.

Recommended Security Measures

In response to the breach, it is critical to treat all exposed credentials as compromised and rotate them immediately. The RTKBase instance should be taken offline and thoroughly audited, while network segmentation and billing system access logs must be reviewed.

Cal Water has not yet made a public statement regarding the breach. SecurityWeek has reached out for a comment and will update with any responses.

Background on Handala

Handala has been active since at least 2008 and is associated with Iran’s Ministry of Intelligence and Security (MOIS). The group, also known by names such as Banished Kitten and Red Sandstorm, engages in activities ranging from hacktivism to data exfiltration and destructive attacks.

Dataminr suggests that Handala’s operational pattern typically involves initial claims followed by escalated actions. Security teams should consider the potential for further destructive activities and adjust their postures accordingly.

Security Week News Tags:Cal Water hack, cyber attack, Cybersecurity, data breach, Handala, infrastructure security, Iranian hackers, PII leak, Threat Actors, US utilities

Post navigation

Previous Post: Chinese Hackers Exploit Linux Login Systems for Years
Next Post: OnyxC2 Malware Exploits 210 Apps to Steal Credentials

Related Posts

Alice Secures 0M to Enhance AI Security Measures Alice Secures $140M to Enhance AI Security Measures Security Week News
McDonald’s Chatbot Recruitment Platform Leaked 64 Million Job Applications McDonald’s Chatbot Recruitment Platform Leaked 64 Million Job Applications Security Week News
160,000 Impacted by Valsoft Data Breach 160,000 Impacted by Valsoft Data Breach Security Week News
Urgent Replacement of Discontinued Edge Devices Advised Urgent Replacement of Discontinued Edge Devices Advised Security Week News
AI Fuels Surge in Google’s Chrome Vulnerability Discoveries AI Fuels Surge in Google’s Chrome Vulnerability Discoveries Security Week News
Mobile Security: Verizon Says Attacks Soar, AI-Powered Threats Raise Alarm Mobile Security: Verizon Says Attacks Soar, AI-Powered Threats Raise Alarm Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark