Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iran-Linked Group Claims Cal Water Cyber Breach

Iran-Linked Group Claims Cal Water Cyber Breach

Posted on June 13, 2026 By CWS

An Iranian-affiliated cyber group, known as Handala, has recently claimed responsibility for breaching the security of California Water Service (Cal Water). The group reportedly released 5 gigabytes of data allegedly obtained from the US water utility, in what they describe as a response to the US’s recent activities in Iran.

Details of the Cyber Intrusion

The hacking group publicized their actions on their blog, stating that while they had the potential to disrupt water services, they opted against it. Intelligence firm Dataminr suggests that Handala may have infiltrated Cal Water’s RTKBase, a GNSS base station platform, potentially using it as a springboard to access the billing system.

Cal Water ranks among the most significant investor-owned water utilities in the nation, serving approximately two million individuals across 100 California communities. Dataminr has confirmed that the Chico District of Cal Water was specifically targeted in this attack, with leaked data indicating access to customer billing information and the internal RTKBase application.

Implications of the Data Breach

The breach resulted in the exposure of personally identifiable information (PII), including names, addresses, phone numbers, account numbers, and payment histories. Additionally, administrative credentials for the RTKBase platform and NTRIP source passwords were compromised. The hackers also enumerated IP addresses connected to Cal Water’s NTRIP network across seven districts.

Although no operational technology (OT) or industrial control system (ICS) disruption has been confirmed, Dataminr warns that Handala’s toolkit includes custom wipers and MBR-overwriting capabilities. This indicates a potential for destructive actions, similar to previous incidents involving the group.

Recommended Security Measures

In response to the breach, it is critical to treat all exposed credentials as compromised and rotate them immediately. The RTKBase instance should be taken offline and thoroughly audited, while network segmentation and billing system access logs must be reviewed.

Cal Water has not yet made a public statement regarding the breach. SecurityWeek has reached out for a comment and will update with any responses.

Background on Handala

Handala has been active since at least 2008 and is associated with Iran’s Ministry of Intelligence and Security (MOIS). The group, also known by names such as Banished Kitten and Red Sandstorm, engages in activities ranging from hacktivism to data exfiltration and destructive attacks.

Dataminr suggests that Handala’s operational pattern typically involves initial claims followed by escalated actions. Security teams should consider the potential for further destructive activities and adjust their postures accordingly.

Security Week News Tags:Cal Water hack, cyber attack, Cybersecurity, data breach, Handala, infrastructure security, Iranian hackers, PII leak, Threat Actors, US utilities

Post navigation

Previous Post: Chinese Hackers Exploit Linux Login Systems for Years
Next Post: OnyxC2 Malware Exploits 210 Apps to Steal Credentials

Related Posts

South Korea Seeks to Arrest Dozens of Online Scam Suspects Repatriated From Cambodia South Korea Seeks to Arrest Dozens of Online Scam Suspects Repatriated From Cambodia Security Week News
Compyl Raises  Million for GRC Platform Compyl Raises $12 Million for GRC Platform Security Week News
Censys Secures M to Boost Internet Intelligence Censys Secures $70M to Boost Internet Intelligence Security Week News
Chrome, Edge Extensions Caught Tracking Users, Creating Backdoors Chrome, Edge Extensions Caught Tracking Users, Creating Backdoors Security Week News
Fortinet, Ivanti Patch High-Severity Vulnerabilities Fortinet, Ivanti Patch High-Severity Vulnerabilities Security Week News
Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed
  • Gentlemen Ransomware Hits 478, Spreads Like a Worm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed
  • Gentlemen Ransomware Hits 478, Spreads Like a Worm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark