Summary
Key Points:
- Handala, an Iran-linked threat group, breached California Water Service (Cal Water) via an exposed GPS tool, accessing a customer billing database and leaking 5GB of sensitive data.
- The breach potentially impacts 2 million customers, exposing personally identifiable information (PII) and administrative credentials for critical systems. While no immediate disruption to water services was confirmed, the group has a history of escalating from data theft to destructive attacks.
- Immediate actions recommended include rotating all exposed credentials, taking RTKBase instances offline for audit, and enhancing network segmentation between the GPS infrastructure and billing systems.
Technical Details: The breach involved exploiting an open-source GNSS base station platform (RTKBase) accessible via HTTP on port 10000. Administrative credentials were leaked in plaintext, facilitating access to sensitive customer data.
MITRE ATT&CK Techniques:
- T1078 - Valid Accounts (Defense Evasion)
- T1190 - Exploit Public-Facing Application (Initial Access)
- T1003.001 - OS Credential Dumping: LSASS Memory (Credential Access)
IOCs Mentioned: None mentioned.
Join the discussion — sign up to comment, upvote, and save articles.