In early June 2026, hackers released a large file containing personal information of California residents. The group, Handala, which is linked to Iran, claimed they could shut off water for almost two million people but chose not to. They had not accessed the main water controls. Instead, they exploited a satellite mapping tool called RTKBase, used by workers to find underground pipes. This allowed them to steal customer data and administrative passwords from areas like Bakersfield, Salinas, Stockton, San Mateo, and Chico. Security experts warn that this stolen data puts customers at risk of targeted phishing scams.
The cyberattack worried cybersecurity experts because Handala acts for Iran's intelligence ministry. Their attacks on US targets increased after military clashes between the two countries. Handala said the water system breach was revenge for US military actions. Earlier, the same group had disrupted operations at the medical company Stryker.
Security executive John Gallagher called the breach a dangerous warning. Intelligence firm Dataminr noted that Handala often follows data leaks with more damaging attacks. This incident highlights a recent government warning about Iranian operatives searching for weaknesses in US water systems.
Recognizing the danger to essential services, major companies are building new defenses. Days after the California incident, SoftBank Group in Tokyo announced a partnership with OpenAI. They created a cybersecurity initiative called SB OAI Japan GK, introducing a defense system named "Patching as a Service" to protect Japan's critical infrastructure. This system uses artificial intelligence and telecommunications to find and fix digital weaknesses in company networks. SoftBank plans to offer this service to thousands of important Japanese companies in sectors like aviation, energy, and transportation. SoftBank founder Masayoshi Son has invested heavily in OpenAI, predicting a rise in AI-powered cyberattacks and vowing to use advanced AI to defend against them.