Threats · 89 days ago
The bigger risk is not the leaked billing files. An internal GPS correction service can sit close enough to field operations that admin access there becomes a bridge from ordinary IT into the workflows that support water infrastructure.
Dataminr assessed that Handala’s 5 GB haul from California Water Service included billing records, PII, and admin access tied to Cal Water’s internal RTKBase deployment. Cal Water says it sees no operational disruption so far, but the reported RTK setup is used by field crews for centimeter-level positioning across service districts.
If that assessment holds, this is not just a customer-data breach. It shows how a support system built for mapping and positioning can carry operational trust, and that makes internal fleet, GIS, and correction services worth treating as potential lateral paths into OT-adjacent environments.
3 sources covering this story
California water utility probes breach claim by Iran-linked actor
The group Handala said it attacked one of the nation’s largest water companies.
Cal Water Investigating Iranian Hackers’ Claims
California Water Service says there is no indication of operational disruptions to its water and wastewater systems.
Read the latest: Iran-linked Handala group targets Cal Water, exposing potential pathways between IT and OT environments on Industrial Cyber.
Part of the PlainSec briefing for 2026-06-18