惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Application and Cybersecurity Blog
Application and Cybersecurity Blog
S
Security Archives - TechRepublic
H
Heimdal Security Blog
Webroot Blog
Webroot Blog
Google DeepMind News
Google DeepMind News
S
SegmentFault 最新的问题
Latest news
Latest news
T
Tailwind CSS Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Attack and Defense Labs
Attack and Defense Labs
T
Troy Hunt's Blog
S
Secure Thoughts
Spread Privacy
Spread Privacy
S
Security @ Cisco Blogs
Jina AI
Jina AI
The Cloudflare Blog
Project Zero
Project Zero
Schneier on Security
Schneier on Security
T
Tenable Blog
O
OpenAI News
博客园_首页
博客园 - 司徒正美
Last Week in AI
Last Week in AI
量子位
N
News | PayPal Newsroom
N
News and Events Feed by Topic
爱范儿
爱范儿
V
Visual Studio Blog
Cloudbric
Cloudbric
NISL@THU
NISL@THU
博客园 - 叶小钗
H
Hacker News: Front Page
宝玉的分享
宝玉的分享
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hackread – Cybersecurity News, Data Breaches, AI and More
C
Cybersecurity and Infrastructure Security Agency CISA
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
W
WeLiveSecurity
V
V2EX
P
Palo Alto Networks Blog
G
GRAHAM CLULEY
F
Fortinet All Blogs
Hugging Face - Blog
Hugging Face - Blog
AWS News Blog
AWS News Blog
I
Intezer
Vercel News
Vercel News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
Vulnerabilities – Threatpost
Scott Helme
Scott Helme
T
Tor Project blog

Hackread – Cybersecurity News, Data Breaches, AI and More

Over 50 Android Apps Found Spreading MagicAd Trojan via Official Stores Hackers Hide New Argamal Malware Inside Working Hentai Games Extradited Ukrainian Man Admits Role in Conti Ransomware Attacks Atomic Arch Campaign Hijacks 20+ Linux AUR Packages to Deliver Malware ShinyHunters Target Universities in Oracle PeopleSoft Zero-Day Attack The SpaceX Pre-IPO Market: How Crypto Rails Are Opening Synthetic Access Feds Seize AudiA6 and Dark2Web in $389M Crypto Laundering Case ShinyHunters Leak 40GB of University of Nottingham Student Data Authorities Dismantle Decade-Old SniperDZ Phishing Network Criminal IP at Infosecurity Europe 2026: Introducing AITEM, the Next Chapter of Attack Surface Management Hackers Use Fake Claude Code Guide and AI PDFs to Spread AsyncRAT Malware The Hidden Security Risks of Poor Software Testing FBI Seizes China-Linked Fake Consulting Sites Targeting US Clearance Holders How to Turn Images into Animated Videos with AI: A Wondershare Filmora Guide Scammers Use TikTok and Instagram Reels to Spread Vidar Infostealer ServiceNow Discloses Security Incident Exposing Customer Data Cloud Security Report Finds Fragmented Tools Widening the Cloud Complexity Gap Microsoft June 2026 Patch Tuesday Fixes 206 Flaws and 3 Zero-Days Network Log Analysis: Why Collecting Logs is Not Enough E-Signature Security Checklist Before Selecting an E-Signature Tool Maine Govt Portal Lists 10M Discord Data Breach Notice, But Filing Shows Red Flags Handala Claims Israeli Radar Hack, But Evidence Shows Phone Admin Panel WhatsApp Says It Blocked Pegasus Spyware Campaign Linked to NSO Operation FlutterBridge Uses Fake Google Ads to Spread macOS Backdoor Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware Silent Ransom Group Uses Fast Flux Botnet to Hide Law Firm Leak Sites New Pink Extortion Group Targets Microsoft 365 Cloud Data Via Vishing Scams Miasma Malware Hits 32 Red Hat Packages via Compromised GitHub Account Atlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service Users Reaper macOS Infostealer Abuses Script Editor to Steal Crypto and Passwords iFood Confirms Data Breach Affecting 1.2 Million Users in Brazil Why eSIMs Are Replacing Traditional SIM Cards Lazarus Group Uses npm Brandjacking Campaign to Target Developers Five Eyes Warns Chinese Spies Are Using Fake Job Ads to Target Military Staff How to Recover Data from iCloud Backup Without Resetting Your iPhone China-Linked TA4922 Hackers Target UK, Europe With New SilentRunLoader Malware Alcasec, "Robin Hood of Spanish Hackers," Jailed for 31 Months Over Data Theft Fake ChatGPT Desktop App Ads Used to Push Password-Stealing Malware Hackers Abused Meta’s AI Support Bot to Hijack Major Instagram Accounts New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions Halo Security Honored with 2026 MSP Today Product of the Year Award Why Encrypted File Sharing Is Essential for Modern Businesses What One Predator Case Can Reveal About an Online Platform’s Safety Gaps RaccoonLine Publishes 2026 dVPN Buyer’s Guide for Privacy-Focused Users How to Get a Reddit API Key in 2026: Step-by-Step Guide Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts How to Get the Most From Your Explainer Video Production Services Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives 27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users The Deliverability Problem: How New Platforms Are Solving Inbox Placement The CISO Whisperer's Watch List For The Gartner Security & Risk Management Summit 2026 Can Big Data Predict Market Movements Accurately? Iran’s Nimbus Manticore Used Trojanized Zoom Installers Against US Firms How Can MSSPs Scale Threat Detection Without Burning Out Their Analysts? Link11 is fully committed to Europe and is opening a Customer Excellence Hub in Lisbon Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning Claude Mythos AI Identified 10,000+ Software Vulnerabilities in One Month FBI Chief Kash Patel’s Clothing Store Hacked in ClickFix Infostealer Attack Netherlands Busts Bulletproof Hosting Network Linked to Disinfo and Cybercrime
Handala Hacking Group Claims Breach of California Water Service
Deeba Ahmed · 2026-06-15 · via Hackread – Cybersecurity News, Data Breaches, AI and More

The Iran-linked hacking group Handala has struck again, this time targeting the California Water Service (Cal Water). The group, which security researchers have been tracking closely throughout 2026, claims this move is retaliation for US actions in Iran.

Cal Water is a major utility serving two million people across 100 communities in California, making this a worrying event for public infrastructure.

The Attack on Cal Water

On 11 June 2026, the research firm Dataminr spotted the group boasting about a breach, publishing five gigabytes of data. While experts confirmed that the customer records from the utility’s Chico District were definitely hit, the leaked files also exposed network infrastructure across seven distinct operational areas, which include Bakersfield, Chico, Salinas, Stockton, Visalia, San Mateo, and a regional engineering segment.

Reportedly, leaked data comprises names, home addresses, phone numbers, account numbers, and payment history accessed from a customer billing database.

The hackers also gained access to an internal system called RTKBase. This is a basic tool used by field crews to get precise GPS data for mapping and fixing water pipes. By stealing passwords from this system, the hackers managed to move over into the billing network.

While Handala claimed in their posts that they had the power to shut off water supplies, they haven’t done so. Security teams note that while Handala has a history of using destructive software to wipe computer systems in other campaigns, they haven’t yet tampered with water treatment processes.

Handala Hacking Group Claims Breach of California Water Service
A screenshot that the Handala hacking group claims was taken from the targeted water service’s internal billing dashboard

A Pattern of Exaggeration

This incident follows several other attacks linked to Handala in 2026, and as observed lately, this group often mixes genuine data theft acts with exaggerated and unverified claims. As Hackread.com reported in March, they claimed to have hit the medical technology firm Stryker and the payment company Verifone.

While Stryker admitted to some network trouble, Verifone found no signs of a breach. Handala claimed to have wiped 200,000 devices at Stryker, but investigators haven’t verified these figures.

The group also hacked the personal Gmail account of FBI Director Kash Patel in March, releasing his resume and travel photos to mock US cyber defence. Earlier this month, they claimed to have shut down Israeli military radar networks. However, SOCRadar’s investigation revealed the hackers had only accessed a local town hall’s telephone routing system.

Following the incident, Cal Water has been advised to change all exposed passwords immediately and separate its mapping systems from customer billing networks to prevent future issues. Security teams also remain on alert for further activity.

Experts’ Perspectives

Industry experts shared their comments with Hackread.com regarding the incident. Sean Malone, Chief Information Security Officer at BeyondTrust, highlighted that the group’s claims of operational control are highly suspect:

“Nothing in the published evidence supports Handala’s claim that it can shut off water in U.S. cities. Dataminr assesses that the group reached a GPS correction server and a customer billing database. Neither system controls water treatment or distribution, and Dataminr states that OT or ICS disruption is not confirmed in this incident.

“As BeyondTrust noted in its Epic Fury threat advisory, Handala has a record of overstating its capabilities. The boast about choosing to spare the water supply reads as the psychological operation itself,” Sean argued.

John Gallagher, Vice President at Viakoo, provided context on how the hackers managed to access the utility’s business and physical networks, warning that this tactic is an escalating problem for critical infrastructure:

“There can be parallels made to the Colonial Pipeline shutdown, where threat actors were able to leverage a billing server to impact pipeline operations. This was the reverse (going from operational systems to a billing server), which demonstrates that pivot points between the two domains are being exploited,” John explained.

“Organizations should not delay in reviewing key protections, especially in eliminating pivot points between OT/IoT and corporate networks, and must enforce strict, zero-trust network segmentation. IoT applications, telemetry platforms, and smart infrastructure must reside on isolated networks completely separated from business systems like billing, email, or corporate databases. An asset compromise on the operational side should never grant access to enterprise data,” he warned.