Hanzala, also referred to as Hanzala cyber group, is a threat actor that has publicly claimed intrusions against U.S. water utilities and an Israeli-linked official. Reported activity includes claims of unauthorized access to water utility systems in multiple California cities and a claimed compromise of a senior Israeli-linked official's email account, with the actor asserting that it obtained a large volume of confidential correspondence and exposed it publicly. The available reporting ties the group to intrusion claims and data-theft messaging, but independent verification is limited for some of those claims. The actor's observed behavior indicates a focus on initial access to exposed systems and subsequent unauthorized access to sensitive information. In the water-sector context, Hanzala publicly framed its claimed access as a warning rather than a disruptive operation, suggesting coercive or signaling intent. In the email-compromise case, the group claimed theft and public release of sensitive communications, consistent with exfiltration and influence-oriented or politically motivated disclosure activity. Based on the supplied facts, Hanzala is best characterized as a politically motivated cyber actor associated with anti-Israeli messaging and claimed targeting of U.S. critical infrastructure and Israeli-linked individuals.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed breaches of water utility systems in multiple California cities and said it withheld disruption as a warning.
Claimed breaches of water utility systems in several California cities as a warning to Washington, while stating it had refrained from disrupting water supplies.
Claimed compromise of the email account of a senior Israeli-linked official and theft/public release of more than 100,000 sensitive emails.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.