Skip to content
Data breachContained

Handala claims breach of California Water Service billing and GPS systems

Iran-linked hacktivist persona Handala claimed to have breached California Water Service, one of the largest U.S. investor-owned water utilities, leaking about 5 GB of customer billing data and credentials as retaliation for U.S. strikes in Iran; Cal Water found no disruption to water operations.

Victim
California Water Service (Cal Water)

On 11 June 2026, the Handala hacking persona, which researchers link to Iran's Ministry of Intelligence, claimed to have compromised California Water Service (Cal Water), one of the largest investor-owned water utilities in the United States, serving about two million customers across roughly 100 California communities. The group published a 5 GB "proof" package on its blog and named the Bakersfield, Visalia and Chico service areas among those affected.

Handala framed the operation as retaliation for U.S. military strikes that, on 10 June, damaged two water reservoirs in the southern Iranian port town of Sirik. The group said it had "deliberately avoided" any attempt to disrupt water distribution.

What was exposed

According to analysis of the leaked material by Dataminr, the dump came from two systems: a customer billing database and an RTKBase/NTRIP GPS correction server used for surveying. Exposed data reportedly included customer names, addresses, phone numbers, account numbers and payment history, as well as plaintext administrative credentials for the GPS platform. Handala also claimed access to customer relationship management systems and internal credentials.

Cal Water said it was taking the claim "very seriously," was working with forensic investigators and federal and state law enforcement, and that preliminary findings showed no operational disruptions to water systems or customer billing. Check Point Research assessed that, if the published evidence was authentic, the attackers had reached IT systems only, not the operational technology controlling water distribution.

Why it matters

The claim came the same month the U.S. and Iran exchanged military blows, and it fits Handala's 2026 pattern of hack-and-leak and destructive operations against Western targets, including the earlier Stryker wiper attack. Even without touching industrial controls, the leak of customer data and infrastructure credentials from a major water utility shows how geopolitical conflict now reaches U.S. critical infrastructure through exposed, lightly secured IT services.

Timeline

  1. U.S. military strikes damage two water reservoirs near Sirik, Iran, the event Handala later cites as its motive.

  2. Handala claims a compromise of California Water Service and publishes a roughly 5 GB proof package.

  3. Cal Water says it is investigating with forensic experts and law enforcement and has found no disruption to water systems or customer billing.

Sources

  1. cybersecuritydive.comhttps://www.cybersecuritydive.com/news/california-water-utility-breach-iran-hacker/823148/
  2. dataminr.comhttps://www.dataminr.com/resources/intel-brief/cyber-intel-brief-handala-claims-breach-of-california-water-service/

Related incidents