Handala’s American water claim rests on a record researchers have already disputed twice
An Iranian-linked group says it breached California Water Service and the FBI director’s personal email. The same group’s Saudi Aramco claim was found to be recycled data.
The National, in Abu Dhabi, reported on 2 September that “Iran’s cyber attacks on US critical infrastructure, including water and energy systems, have intensified following American and Israeli strikes on the country”, and recorded that “the Iranian-linked group Handala claimed responsibility for breaching California Water Service and hacking FBI director Kash Patel’s personal email” and cloud storage. Neither the utility nor the Bureau appears on the record confirming anything in the material this desk holds. The same day, NBC News reported that Iranian hackers had targeted US telecommunications, energy and water systems “according to four people with access to government and industry information about cyberthreats” — four sources, all anonymous, and described as holding access to information rather than first-hand knowledge. A Fox News segment on 3 September featured House Intelligence Committee chairman Rick Crawford and TJ Sayers of the Center for Internet Security warning on the same theme; that is a network summary, not a transcript.
Against that sits a documented pattern. Industrial Cyber, summarising Symantec, records that Handala claimed multiple high-profile breaches through late 2025 and early 2026, and that “some claims, including an alleged breach of Saudi Aramco, appear exaggerated or based on previously circulating data, suggesting potential information or psychological operations aimed at generating a” perception of capability. Symantec’s own write-up gives a second instance: in December 2025 the group said it had compromised the phones of former Israeli prime minister Naftali Bennett and Benjamin Netanyahu’s chief of staff Tzachi Braverman and leaked material from them, but “analysis by researchers disputed some of these claims, saying that the attacks appeared to be” less extensive than presented. The Canadian Centre for Cyber Security’s February bulletin describes the sober baseline: DDoS, defacement, ransomware, wiper malware and hack-and-leak.
Assessment: The asymmetry here is the point. A claim costs nothing to make and travels in hours; a forensic disconfirmation takes weeks and reaches a fraction of the audience. Handala’s record gives two vendor-documented instances of inflation, which is enough to move the burden of proof onto the claimant rather than the utility. Treat the California Water Service and Patel claims as unresolved until someone with access to the systems says otherwise, and note that the likeliest outcome is neither confirmation nor denial but silence — which will be read by many as confirmation. This desk could not verify the 17–20 September window itself; that failure is stated rather than papered over.