Particle.news

Iran‑Linked Hackers Say They Penetrated California Water Systems

The group posted screens it says show customer billing and GPS tools and called the access a warning after U.S. strikes on Iranian reservoirs.

Overview

  • Handala published its claim on Friday and posted screenshots it says include internal dashboards, customer billing records, authentication logs, and GPS monitoring interfaces for multiple California locations.
  • The group framed the operation as retaliation for U.S. airstrikes on June 10 that Iran says damaged two reservoirs in Sirik and left about 20,000 people without safe drinking water.
  • Security firms say the leak appears to include personal data and administrative credentials and that the intruders likely used a GNSS/RTKBase system to move into a billing environment, with Cal Water’s Chico district identified by researchers as affected.
  • Analysts track Handala to Iran‑linked actors and warn the group has both data‑theft and destructive tools, though independent verification of full system access and any service disruption is limited and Cal Water has not publicly confirmed the incident.
  • Cybersecurity experts say the claim raises humanitarian and escalation risks because targeting water systems can endanger civilians and could signal increased use of state‑aligned cyber reprisals in the U.S.–Iran confrontation.