RTKBase Credentials Turned a Water Leak Into Pivot Risk

The break is the trust inside the utility network. A live RTKBase GNSS platform appears to have been the doorway into Cal Water’s billing environment, so the story is not just stolen data but a move from an operational support system into customer records and admin credentials. SecurityWeek reports Handala published 5 GB of data tied to Cal Water, and Dataminr says the likely entry point was RTKBase before lateral movement into billing. The dump reportedly includes customer PII, RTKBase administrative credentials, and an NTRIP source password, which means the exposed secrets may reach beyond one system and back into the GNSS platform itself. For water utilities, the risk is any support system that can talk to finance or customer databases. Once those credentials are out, patching the original box does not close off reuse across other reachable systems.

Part of the PlainSec briefing for 2026-06-13

Sources