California Water Service (Cal Water) has investigated a recent cyberattack claimed by the Iranian hacker group Handala, finding no evidence of activity in the water utility's operational technology (OT) environment.
Investigation Findings
Handala, believed to be a front for Iranian government hacking operations, claimed it could have disrupted the water supply after gaining access to Cal Water systems but decided not to do so. The threat actor leaked 5 GB of data allegedly taken from Cal Water systems, which included personal information and evidence of a compromised customer billing system and internal application.
Cal Water hired cybersecurity experts, including Google's Mandiant unit, to assist with the investigation. Mandiant confirmed that the threat actor activity was limited to unauthorized access to a small number of specific user accounts within two third-party service provider platforms.
Compromised Systems
The investigation determined that the threat actor accessed one active customer's online Cal Water account using stolen user credentials. However, the customer account did not provide access to the billing system, and no payment information was compromised. The threat actor also accessed an external, third-party website related to a GPS location correction tool, which did not contain any confidential or sensitive information.
Water Sector Vulnerabilities
The water sector continues to be a prime target for threat actors due to its heavy reliance on legacy systems and often inadequate cybersecurity measures. Cal Water appreciated the collaboration and support from state and federal government partners throughout the investigation and will continue to work to maintain the security of its systems and data from malicious actors.
Related incidents, such as the Lantronix Serial-to-IP Converter flaw exploitation and the Accenture acquisition of a majority stake in Dragos, highlight the importance of robust cybersecurity measures in the water sector and beyond.
Expert Insights
Cybersecurity experts emphasize the need for organizations to prioritize cybersecurity, particularly in critical infrastructure sectors like water and energy. The use of legacy systems and inadequate cybersecurity measures can leave these organizations vulnerable to cyberattacks, which can have severe consequences.
In the face of increasing cyber threats, it is essential for organizations to invest in robust cybersecurity measures, including regular security audits, employee training, and incident response planning. By taking proactive steps to secure their systems and data, organizations can reduce the risk of cyberattacks and protect their customers and assets.
- California Water Service (Cal Water) investigated a cyberattack claimed by Iranian hacker group Handala.
- No evidence of operational technology environment breaches was found.
- The threat actor leaked 5 GB of data allegedly taken from Cal Water systems.
- Cal Water hired cybersecurity experts, including Google's Mandiant unit, to assist with the investigation.
- The water sector is a prime target for threat actors due to its heavy reliance on legacy systems and often inadequate cybersecurity measures.
The investigation determined that the threat actor accessed one active customer's online Cal Water account using stolen user credentials. - California Water Service
As the water sector continues to evolve and become increasingly reliant on digital technologies, it is essential for organizations to prioritize cybersecurity and invest in robust measures to protect their systems and data from malicious actors.
Source: SecurityWeek