Close Menu
  • Tech Insights
  • Laptops
  • Mobiles
  • Gaming
  • Apps
  • Money
  • Latest in Tech
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
TechzLab – Tech News, Gadgets, Mobile, IT Updates & ReviewsTechzLab – Tech News, Gadgets, Mobile, IT Updates & Reviews
  • Tech Insights
  • Laptops
  • Mobiles
  • Gaming
  • Apps
  • Money
  • Latest in Tech
TechzLab – Tech News, Gadgets, Mobile, IT Updates & ReviewsTechzLab – Tech News, Gadgets, Mobile, IT Updates & Reviews
Home » Iran-linked hackers breached a California water utility serving millions and published everything they found online
Laptops

Iran-linked hackers breached a California water utility serving millions and published everything they found online

By June 19, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Micron purchases treated water from Veolia, a private municipal water utility
Share
Facebook Twitter LinkedIn Pinterest Email

  • Iranian hackers accessed two Cal Water systems and leaked 5GB of data
  • A poorly secured GPS tool gave attackers a direct path inside Cal Water
  • Administrative credentials for seven California districts were published in plaintext online

Tehran-linked threat group Handala has claimed it successfully breached California Water Service and released a 5GB data dump as proof.

Cal Water is one of the largest investor-owned water utilities in the United States, serving millions of residential and commercial customers across California.

Handala described the breach as direct retaliation for recent US military actions in Iran, claiming it could disrupt water access but deliberately chose not to — for now.

Latest Videos From

How a GPS tool became the entry point

Cybersecurity firm Dataminr analyzed the published data and identified two separate systems that Handala accessed during the breach.

The first was a customer billing database containing names, addresses, phone numbers, account numbers, and payment histories across multiple Cal Water districts.

You may like

The second was an internal RTKBase deployment — an open-source GPS base station platform used by field crews maintaining water infrastructure across California.

The RTKBase instance had been running continuously for approximately 783 hours at the time of access, with GPS correction data streaming across seven identified Cal Water districts.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Those districts included Bakersfield, Chico, Salinas, Stockton, Visalia, San Mateo, and a regional engineering segment spread across California.

The researchers believe that the GPS platform was not the end goal — it was the entry point into deeper infrastructure.

The RTKBase web interface was accessible via standard HTTP port 10000 across multiple district locations, making it straightforward for outside actors to locate and access.

What to read next

It was deployed on lightweight hardware that offered minimal resistance against unauthorized entry from the internet.

Administrative credentials for the platform appeared in the published dump in plaintext, giving anyone who downloaded it immediate access to the entire system.

Full network infrastructure details for all seven districts were equally exposed, leaving Cal Water’s security team with virtually nothing intact to protect.

A pattern that should concern every water utility

Handala’s history makes the “chose not to disrupt” framing worth treating with considerable skepticism from any serious security perspective.

The group deployed a destructive wiper against Stryker in March 2026 that disrupted manufacturing and shipping — following the same data-theft-first pattern documented in this breach.

“Handala’s operational pattern frequently involves an initial claim followed by escalated action,” Dataminr’s report concluded.

“Security teams should treat the current disclosure as a possible precursor to a destructive follow-on and posture accordingly.”

The US Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory this year warning of Iranian groups targeting US water sector technologies.

This breach is an indication that Iranian cyber threats to US water infrastructure are no longer theoretical.

Cal Water has not publicly acknowledged the breach, but affected customers now face elevated phishing risks given that their names, addresses, phone numbers, and account details are publicly available.

Via Security Affairs


Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

I think the Surface Laptop for Business might be the smartest and most effective work device Microsoft has ever produced — but I’m most enamored with this one key privacy feature

July 28, 2026

The Best Laptops We’ve Tested for Kids in 2026 – PCMag

July 27, 2026

It’s not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files

July 26, 2026
Leave A Reply Cancel Reply

Comment moderation is enabled. Your comment may take some time to appear.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest
  • Samsung Galaxy Z Fold 8 review: a shot in the arm for the foldables market August 3, 2026
  • Best MagSafe wallets of 2026: Expert tested and reviewed August 3, 2026
  • ‘It’s without a doubt one of the least detrimental privacy-focused solutions to your mobile experience’: I spent a month testing GrapheneOS — and it almost made me ditch my Android phone entirely July 30, 2026
  • Low-power AI could define the next era of global innovation July 30, 2026
  • NYT Strands hints and answers for Wednesday, July 29 (game #878) July 29, 2026
We are social
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest creative news from Techzlab.

Tags
AI Amazon Anthropic Apple artificial intelligence ChatGPT cybersecurity data centers defense tech Donald Trump electric vehicles Elon Musk evergreens EVs Exclusive Fintech gemini Google Grok In Brief India Layoffs Meta Microsoft Mythos nvidia nvidia gtc Nvidia GTC 2026 Openai Perplexity Polymarket Redwood Materials sam altman Sequoia Capital siri social media Softbank SpaceX Spotify Tesla Tim Cook Truecaller Uber Windows X
Archives
Quick Link
  • Apps (403)
  • From the Editor (4)
  • Gaming (382)
  • Laptops (405)
  • Latest in Tech (404)
  • Mobiles (405)
  • Money (228)
  • Tech Insights (406)
Don't miss

Best MagSafe wallets of 2026: Expert tested and reviewed

August 3, 2026

I tested a premium Linux laptop that’s as light as it is powerful – here’s why I love it

July 29, 2026

Is the Electric Trike the Next Big Thing in Shared Micromobility?

July 28, 2026
Follow us
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
© 2026 Techzlab.com Designed and Developed by WebExpert.
  • Home
  • From the Editor
  • Money
  • Privacy Policy
  • Contact

Type above and press Enter to search. Press Esc to cancel.