
HANDALA hackers have claimed a breach of California Water Service, saying they accessed the personal details of roughly two million customers while insisting they could have disrupted water supply but opted not to.
The group released a five‑gigabyte data dump that contained names, addresses and account information, although no financial records appear to have been taken.
Cal Water launched an investigation with the help of Mandiant and state officials, and has so far found no indication that operational technology was affected.
Dataminr’s intelligence brief, which first flagged the claim, notes that the intrusion appears to have started from a third‑party GPS tool used for surveying.
Initial entry is reported to have come through the utility’s RTKBase platform, a real‑time kinematic GPS system that provides precise location data for field operations.
From there attackers moved laterally into the customer billing database, extracting roughly five gigabytes of information.
The exposed data includes personal identifiers such as full names, home addresses and service account numbers, but does not cover payment card details or bank information.
No malware was detected on the OT network and controllers that manage water flow remained unchanged according to the forensic review.
Handala describes itself as an Iran‑linked hacking collective and framed the intrusion as retaliation for recent US actions against Iran.
Despite their claim of being able to cut off water distribution, investigators from Cal Water and federal partners uncovered no evidence of service interruption or tampering with pump stations.
The group has a track record of targeting critical infrastructure and has shown a willingness to increase the scope of its operations over time.
Analysts warn that the absence of physical disruption in this case does not reduce the strategic value of the data stolen.
The breach highlights a recurring theme in water sector cybersecurity: third‑party monitoring and sensing tools often sit at the intersection of IT and OT networks.
When such tools are not properly hardened or segmented, they can provide a foothold for attackers seeking to pivot toward more sensitive systems.
Many utilities continue to run ageing OT equipment alongside modern billing and customer‑service platforms, creating a complex attack surface that defenders must manage.
Regulators and industry groups are urging owners to inventory all external‑facing applications and enforce strict access controls.
Organisations should rotate any passwords or API keys that may have been harvested from the RTKBase environment and enforce multi‑factor authentication on all remote access points.
A thorough review of third‑party software for unpatched vulnerabilities is essential, with priority given to any tool that can communicate with both IT and OT zones.
Network segmentation must be verified so that a compromise in a sensing device cannot reach billing servers or control systems without triggering alerts.
Enhanced logging, including authentication attempts and file transfers, should be retained for at least ninety days and fed into a security information and event management system.
Security teams should monitor for signs of lateral movement, such as unusual admin logins or unexpected data exfiltration, and share any indicators of compromise with trusted ISACs.
Incident response plans ought to be exercised against scenarios that combine data theft with a potential OT impact, ensuring that playbooks cover both outcomes.
Treating the water supply chain as a single asset class and applying the same rigour to OT as to IT can lower the chance that a future intrusion leads to both loss of privacy and disruption of service.
Continuous vigilance, timely patching and clear communication with regulators will be key to defending against similar threats.