Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-18 and was added to the RWP archive on 2026-09-07.
Handala's Cal Water dump was billing and RTKBase — Cal Water said OT did not move
Nozomi's 18 June 2026 note separates a 5 GB customer/GPS-correction leak from a water-process compromise. Cal Water's public line was no disruption to production or delivery.
Bottom line up front
CONFIRMED as reporting: On 12 June 2026 Handala (Iran-linked; sometimes VOID MANTICORE) claimed California Water Service and posted bill screenshots. Dataminr via SecurityWeek/Nozomi: likely exposed RTKBase, then customer billing — names, addresses, phones, accounts, payment history, RTKBase admin creds, NTRIP passwords, district IPs. About 5 GB. Cal Water: preliminary scan showed no compromise of IT water-production and delivery systems; no known operational disruption including billing platform. Process/OT compromise: NOT CONFIRMED. Actor claimed they could have disrupted supply and chose not to — treat as self-report.
Historical backfill of 18 June 2026 Nozomi analysis; added 7 September 2026.
What happened
Geopolitical messaging (retaliation framing around Iranian water infrastructure) used a US utility's customer systems. The GPS-correction/NTRIP layer is adjacent to field survey, not a pump PLC.
Why it mattered
Headlines said "water hack." The evidence said PII and a positioning service. Utilities that panic-patch PLCs while leaving RTK/billing on the internet will miss the actual intrusion class — and the next actor may not stop at screenshots.
Who / what was affected
Cal Water (~2 million customers / 100 communities, per Nozomi). Visalia later said its trash/wastewater billing is separate.
Technical context
Internet-exposed RTK/NTRIP is an IT asset with OT-adjacent geography. Hunt those portals. Do not declare ICS incident without process telemetry.
Exploitation / threat status at the time
REPORTED data theft from billing/RTK.
CONFIRMED (utility statement): no OT disruption in preliminary findings.
UNKNOWN full forensic scope.
What defenders should have done
- Pull survey/GPS correction off the open internet.
- Assume customer PII exposure; legal/notification track separate from ICS.
- Verify PLC/HMI reachability independently of the leak.
RWP assessment
Confidence: High on the "not OT until proven" line. This is why RWP will not copy actor videos into process-impact claims.
Defensive actions
- External attack-surface for RTK, CIS, billing.
- Public comms template: IT vs OT in the first hour.
- Watch the July FBI/EPA PLC PSA as the different water story.
Sources
- Nozomi Networks — Handala's water play: what the breach was, what it wasn't
- SecurityWeek — Cal Water investigating Iranian hackers' claims
- FOX26 — Iranian group claims Central Valley water hack; officials cite no evidence of OT breach