Iranian group Handala gained access to two Cal Water and leaked 5GB of data. A poorly secured GPS tool gave attackers direct access to Cal Water’s internals. Administrative credentials for seven California districts were published in plain text online.
See also: Ford Mustang Mach-E GT California Special combines the old with the new

The Tehran-linked Handala threat group has claimed to have successfully breached the California Water Authority and released 5GB of data as proof. Cal Water is one of the largest private water companies in the United States, serving millions of residential and commercial customers across California.
Handala described the breach as direct retaliation for recent U.S. military actions in Iran, claiming it could have cut off access to the water but chose not to — for now. That statement, however, has drawn skepticism from security experts, given the group’s historical behavior.
Cybersecurity firm Dataminr analyzed the released data and identified two separate systems that Handala accessed during the breach. The first was a customer billing database that contained names, addresses, phone numbers, account numbers, and payment histories across multiple Cal Water regions. This database is critical to the company, as it contains sensitive customer information that could be used for malicious purposes, such as identity theft.
The second was an in-house development of RTKBase — an open-source GPS-based platform used by field crews to maintain water infrastructure across California. The RTKBase installation had been operating continuously for approximately 783 hours at the time of access, with GPS correction data flowing to seven identified Cal Water areas, including Bakersfield, Chico, Salinas, Stockton, Visalia, San Mateo, and a regional engineering division spanning California.
See also: Blue Shield of California: Millions of members' data leaked

The researchers believe that the GPS platform was not the end goal — it was the entry point into deeper infrastructure. The RTKBase web interface was accessible via standard HTTP port 10000 in multiple region locations, making it easy for outsiders to locate and access it. It was developed on lightweight hardware that offered minimal resistance to unauthorized entry from the internet.
The administrative credentials for the platform appeared in the published leak in plain text, giving anyone who downloaded the data direct access to the entire system. The full details of the network infrastructure for the seven regions were also exposed, leaving Cal Water’s security team with almost nothing intact to protect.
Handala’s story makes the “choose not to disrupt” framework worthy of significant skepticism from any serious security perspective. The group deployed a destructive wiper against Stryker in March 2026 that disrupted production and shipping — following the same pattern of initial data theft documented in this breach. Dataminr’s report concluded that security teams should treat the current disclosure as a potential harbinger of a destructive sequel.
This breach highlights the need for increased vigilance and enhanced security measures in critical infrastructures. Organizations managing such infrastructures should review their security policies and ensure that their systems are adequately protected from external threats. The use of open source tools, while offering flexibility and cost-effectiveness, can be a weak point if not accompanied by appropriate security measures.
See also: California Cryobank: Data breach affects customers

Additionally, the leak of administrative credentials in plain text highlights the need for encryption and secure storage of sensitive information. Organizations should invest in training programs for their staff to understand the threats and implement security best practices.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
