HomeSecurityCal Water denies hackers' claims of water outage

Cal Water denies hackers' claims of water outage

The California Water Service (Cal Water) investigation into the recent cyberattack, claimed by the Iranian hacking group Handala , found no evidence of activity in the water utility’s operational technology (OT) environment. Handala, which claims to be a hacktivist collective but is widely believed to be a front for Iranian government hacking operations, said it could have shut off water supply after gaining access to Cal Water’s systems, but chose not to.

See also: ICO imposes $1.3m fine on South Staffordshire Water

Article Image: Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply

The statement hinted that hackers had gained deep access to industrial control systems (ICS).

The attack highlighted the vulnerabilities facing critical infrastructure, such as water utilities, which often rely on outdated systems and inadequate cybersecurity measures. The leak of 5GB of data from Cal Water’s systems included personal information, highlighting the need for increased protection of customer data. Cybersecurity analysts discovered that a customer billing system and an internal application may have been compromised, although Cal Water confirmed that no payment information was accessed.

Cal Water, one of the largest publicly traded water utilities in the United States, has hired cybersecurity experts, including Mandiant , to assist in investigating the cybersecurity incident. Mandiant, with its extensive experience in analyzing and responding to cyberattacks, confirmed that the threat actor’s activity was limited to unauthorized access to a small number of specific user accounts within two third-party service provider platforms.

This means that, despite the severity of the attack, the hackers were not able to penetrate Cal Water's internal IT or business technology environments.

See also: MuddyWater hackers adopt new DarkBeatC2 tool

Cal Water denies hackers' claims of water outage

The investigation determined that the threat actor accessed an active Cal Water customer account using stolen user credentials. The customer account did not provide access to the billing system and no payment information was compromised. Additionally, the threat actor accessed an external, third-party website associated with a GPS location correction tool. However, the website does not contain any confidential or sensitive information.

The organization concluded: “We appreciate the cooperation and support our state and federal government partners have provided us throughout the investigation and will continue to work to keep our systems and data secure from malicious actors.” This statement underscores the importance of collaboration between public and private actors in addressing growing cyber threats.

The water sector continues to be a prime target for threat actors due to its heavy reliance on legacy systems and often inadequate cybersecurity measures. Water infrastructure is critical to public health and safety, and protecting it from cyberattacks is vital. The attack on Cal Water is a reminder of the need to continually upgrade security systems and implement modern protection technologies.

Cal Water, like other water companies, is being called upon to invest in new technologies and strategies to strengthen cybersecurity. This includes training staff, upgrading systems, and implementing protocols to detect and respond to threats in real time. Partnering with specialized cybersecurity companies, such as Mandiant, is an important step in this direction.

See also: Iranian Hackers Target US Critical Infrastructure with PLC Attacks

microplastics

The attack on Cal Water is not an isolated incident, but part of a broader trend of attacks on critical infrastructure. Cybercriminals continue to evolve their methods, making it necessary for companies to adapt and strengthen security measures. Protecting data and systems is a priority to avoid service disruptions and protect customer privacy.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS