Iran-linked Handala claimed a breach of California Water Service (Cal Water) in mid-June, publishing 5 gigabytes of customer data and asserting the group had attained access that could disrupt water distribution across seven Californian cities. Mandiant, brought in by Cal Water, found no evidence of threat actor activity inside the utility’s IT or OT environments — but confirmed that user credentials for two third-party platforms were compromised. The access was real. The claimed OT reach was not.
Attack Path: RTKBase to Billing
Handala’s initial access came through RTKBase, a third-party GNSS base station management platform that Cal Water uses for precision positioning infrastructure. From there the group moved laterally to a billing system. Neither platform connects to water treatment or distribution controls.
The exfiltrated data is a bulk database export containing customer PII: names, addresses, phone numbers, account numbers, and payment histories for systems serving Bakersfield, Chico, Salinas, Stockton, Visalia, San Mateo, and a regional engineering segment. Dataminr’s threat intelligence confirms the scope of exposed network infrastructure documentation across those seven operational areas.
Attribution: MOIS and Banished Kitten
Handala is assessed with high confidence as a Ministry of Intelligence and Security (MOIS) affiliated operation embedded within the broader Banished Kitten Iranian cyber cluster. The group has been operationally active since December 2023 and significantly escalated U.S.-targeted activity following U.S.-Iran military engagement beginning in February 2026. The Cal Water operation was explicitly framed as retaliation for U.S. military operations in Sirik, Iran, with Handala publishing the claim through Iranian state media outlet Press TV.
Despite the hacktivist presentation, the operational profile is consistent with state-directed intelligence collection and influence operations. CISA had previously issued advisories on Handala targeting water and wastewater sector organisations.
Credibility Assessment: OT Claim Does Not Hold
Handala stated it could “shut off water” to U.S. cities. Nothing in the published evidence supports this. The RTKBase-to-billing pivot provides no path to water treatment or distribution SCADA systems. Security researchers across multiple firms who reviewed the published data have flagged the claim as unsupported, consistent with Handala’s established pattern of capability exaggeration for influence purposes.
What remains confirmed: unauthorised access to third-party platforms, credential compromise of a small number of accounts, and exfiltration of customer PII at scale. Mandiant found no evidence of lateral movement into Cal Water’s internal networks beyond the two third-party platforms.
Third-Party Supply Chain as Entry Vector
The attack pattern is significant for water sector and broader critical infrastructure defenders. Handala’s entry was not through Cal Water’s own perimeter — it was through a third-party GNSS management SaaS platform. Niche industrial SaaS tools used at utilities (positioning systems, billing integrations, remote monitoring) frequently have weaker credential hygiene and less frequent security review than core infrastructure, yet they share network adjacency with more sensitive systems.
The breach illustrates a known but underweighted risk: an attacker with access to a third-party platform can move to billing data and network documentation even when the path to OT remains blocked.
Recommended Actions
Water utilities and critical infrastructure operators should audit all third-party SaaS platform access points, enforce MFA on every integration, and verify that positioning, billing, and remote access tools are network-segmented from OT systems. Any credential exposure in a third-party platform warrants immediate incident response — not just a password reset — given the lateral movement potential demonstrated here.
Monitor CISA advisories for updated Handala IOCs as the U.S.-Iran geopolitical situation continues to generate retaliatory cyber operations against U.S. infrastructure.