The Iranian-linked threat group Handala has claimed a breach of California Water Service (Cal Water), one of the largest investor-owned water utilities in the United States, publishing a 5GB proof-of-concept dump that Dataminr analysis confirms contains customer billing PII and administrative credentials for an internal precision GPS correction network. The compromise spans at least seven Cal Water operational districts and serves a utility that supports roughly two million customers across 100 California communities.
What Happened
On June 11, 2026, Dataminr issued a Flash alert detecting a Handala claim of compromise against Cal Water, posted to the group's leak blog in line with its established hack-and-leak playbook. Dataminr analysis of the 5GB proof-of-concept package indicates the actor accessed two distinct Cal Water systems rather than a single environment.
The first is a customer billing database containing personally identifiable information for accounts across multiple districts. Cal Water's Chico District has been identified as a confirmed affected account, with transaction and account records in the dump indicating direct access to the billing environment.
The second is Cal Water's internal RTKBase deployment, an open-source NTRIP caster used by field crews to receive centimeter-accurate GPS corrections while mapping and maintaining water infrastructure. Screenshots in the dump document administrative access to this platform, which had been running for approximately 783 continuous hours at the time of access, streaming correction data across all seven identified district mountpoints.
What Was Taken
The published 5GB dump bundles data from both compromised systems. From the billing side, the actor exposed customer PII including account and transaction records tied to specific service districts. From the operational technology side, the dump includes administrative credentials for the RTKBase platform and at least one NTRIP source endpoint, all of which must now be treated as fully compromised.
The release also enumerates the IP infrastructure behind the NTRIP correction network, which serviced at least seven Cal Water districts: Bakersfield, Chico, Salinas, Stockton, Visalia, San Mateo, and a regional engineering segment. Any system that shares the exposed credentials or sits on the same network segment should be considered at elevated risk of follow-on access.
Why It Matters
This incident sits squarely inside an active, federally flagged campaign. It follows Handala's most significant U.S. operation to date, the March 2026 Stryker wiper attack, and aligns with a 2026 federal advisory specifically warning of Iran-linked targeting of U.S. water sector technologies. The targeting of a major water utility is not incidental; it reflects a sustained interest in critical infrastructure that supports basic public services.
The dual-system nature of the breach is the strategic concern. The exposure of a billing database is a privacy and fraud problem, but the compromise of an internal GPS correction network used by field crews reaches into operational technology that supports physical infrastructure maintenance. The combination signals an actor able to move between customer-facing IT and internal OT-adjacent systems within the same victim.
The Attack Technique
Dataminr assesses the billing system and the RTKBase platform as distinct infrastructure. The RTKBase network is evaluated as a probable initial access vector or lateral pivot point that enabled the actor to reach the billing environment. An RTKBase instance that had been online for 783 continuous hours, internet-reachable to serve corrections to field crews, presents an exposed and likely under-monitored entry surface.
The long uptime and the public enumeration of district mountpoints and IP infrastructure suggest the actor had sustained, unhurried access. With administrative credentials in hand for the caster and at least one NTRIP source, the path from a low-attention OT support system to higher-value customer data is consistent with the lateral-movement model Handala has favored in prior operations.
What Organizations Should Do
- Treat all credentials in the dump as compromised. Immediately rotate RTKBase administrative credentials, the affected NTRIP source endpoint, and any shared or reused passwords across the seven named districts.
- Hunt for lateral movement between OT-adjacent systems and IT billing environments. Review authentication logs and network flows connecting the RTKBase segment to the billing database for the full window covered by the 783-hour uptime.
- Remove internet-facing exposure of RTKBase and NTRIP casters where possible, or place them behind VPN and strict access controls; segment the correction network away from customer data systems.
- Notify affected customers, particularly in the confirmed Chico District, and monitor exposed billing PII for fraud and identity abuse.
- Apply the 2026 federal advisory guidance on Iran-linked water sector targeting, and audit all internet-reachable OT support tooling for similar long-running, under-monitored deployments.
- Preserve the published dump and access artifacts for forensic and law enforcement coordination, and assume Handala will publicize follow-on data to amplify the operation.
Sources: Cyber Intel Brief: Handala Claims Breach of California Water Service - Dataminr