XOOMAR
Cybersecurity concept showing protected water utility infrastructure under a claimed hacker breach
CybersecurityJune 13, 2026· 6 min read· By XOOMAR Insights Team

5GB Cal Water Hack Leak Exposes 2M Customers to Risk

Share
Updated on June 13, 2026

Handala claimed it spared Cal Water customers from a water disruption, but still leaked 5GB of alleged stolen data tied to the utility’s customers and internal systems.

XOOMAR Intelligence

Analyst Take

66/ 100
Moderate
3 sources analyzedLow confidenceTrend10Freshness100Source Trust85Factual Grounding96Signal Cluster20

The Iran-linked group said this week it hacked California Water Service, known as Cal Water, and published data that includes customer personal information and credentials for the RTKBase platform, according to SecurityWeek. Cal Water has not publicly acknowledged the intrusion, and the level of access Handala actually had remains unconfirmed.

Iran-linked Handala says it breached Cal Water and leaked 5GB of files

Handala framed the alleged breach as retaliation for recent US actions in Iran. In its post, the group claimed it had the ability to disrupt water access but chose not to.

That claim is the flashpoint. A data leak is already serious. A credible path into systems adjacent to utility operations would be worse. So far, SecurityWeek reports that OT/ICS disruption has not been confirmed.

Dataminr, the threat intelligence company cited in the report, assessed that Handala likely accessed Cal Water’s RTKBase instance, a GNSS base station platform, before moving laterally to a billing system. GNSS base stations provide correction data for satellite positioning. NTRIP, also referenced in the leak, is a protocol used to stream that correction data.

Cal Water is one of the largest investor-owned water utilities in the US, serving roughly two million customers across 100 communities in California. Dataminr said Cal Water’s Chico District has been confirmed as a victim of the attack.

The leaked data appears to include a bulk customer billing database export. SecurityWeek reported that the dump contains names, addresses, phone numbers, account numbers, payment histories, administrative credentials for RTKBase, and a mountpoint-level NTRIP source password.

“The RTKBase instance had been operational for approximately 783 continuous hours at the time of access, with GPS correction data streamed across all seven identified district mountpoints,” Dataminr said.

That detail matters because it points to a live system, not just an abandoned credential set. It doesn’t prove water service was at risk. It does suggest investigators need to understand whether the RTKBase environment was isolated cleanly from billing and other internal systems.


Leaked customer data and RTKBase credentials raise utility security concerns

The exposed customer records create the most immediate risk. Names, addresses, phone numbers, account numbers, and payment histories can be used to build convincing fraud attempts.

XOOMAR analysis: The danger here is not limited to the data dump itself. When attackers publish customer billing records, follow-on abuse can become more targeted. Customers may receive messages that look more credible because the sender can reference real account or payment details. That inference is grounded in the reported data types, not in any confirmed Cal Water customer fraud campaign.

The credential leak is the sharper technical problem. Administrative RTKBase credentials and an NTRIP source password can give investigators a clue about how the attackers moved, or how far they might have been able to move.

Dataminr separated the environments in its assessment:

“The billing system and RTKBase platform represent distinct infrastructure. The RTKBase network is assessed as a probable initial access vector or lateral pivot point that enabled the actor to reach the billing environment,” the company said.

That sentence is doing a lot of work. It says Dataminr does not treat RTKBase and billing as the same system. It also says the RTKBase environment may have been the bridge.

Area Reported exposure Confirmed disruption
Customer billing data Names, addresses, phone numbers, account numbers, payment histories No service disruption reported
RTKBase platform Administrative credentials No OT/ICS disruption confirmed
NTRIP network Mountpoint-level source password and IP enumeration across seven districts No confirmed manipulation of correction data

Handala’s profile raises the stakes. SecurityWeek reported that the US has linked the group to Iran’s Ministry of Intelligence and Security, and that it is also tracked as Handala Hack, Banished Kitten, Dune, Hanzalah Hacking Group, Homeland Justice, Red Sandstorm, Storm-0842, and Void Manticore.

The group is known for data theft, wiper malware, destructive activity, and psychological operations, according to the source material. Dataminr specifically warned that Handala’s toolkit includes custom wipers and MBR-overwriting capabilities.

For readers following breach-response patterns, XOOMAR has tracked adjacent security pressure points in 13.5GB Tchap Data Breach Puts French Chats at Risk and Langflow Flaw Lets Hackers Write Files on AI Servers. The shared lesson is narrow but practical: exposed data and exposed access paths have to be handled as separate response tracks.

Cal Water customers now wait for breach confirmation, notices, and password resets

The next move belongs to Cal Water. SecurityWeek said it emailed the company for comment and would update its report if Cal Water responded.

Until the utility speaks publicly, several core questions remain open:

  • Acknowledgment: Has Cal Water confirmed the intrusion internally or to customers?
  • Scope: Is the confirmed victim limited to the Chico District, or did other districts have exposed systems?
  • Credential status: Were the RTKBase and NTRIP credentials active when leaked?
  • Access path: Did Handala enter through RTKBase, billing, or another system entirely?
  • Containment: Has the RTKBase instance been taken offline, audited, or segmented from billing systems?

Dataminr’s recommended response is blunt. It said exposed credentials should be treated as compromised and rotated immediately. It also said the RTKBase instance should be taken offline and audited, while network segmentation and billing-system access logs should be reviewed.

Customers don’t have enough confirmed detail to know whether their own records are in the dump. Still, practical caution is warranted. Messages claiming to come from Cal Water should be verified through official channels, especially if they reference account details or request payment changes. Reused passwords tied to utility accounts should be changed.

The larger risk is follow-on action. Dataminr warned that Handala often makes an initial claim before escalating.

“Handala’s operational pattern frequently involves an initial claim followed by escalated action. Security teams should treat the current disclosure as a possible precursor to a destructive follow-on and posture accordingly,” Dataminr said.

That is the watch item now: whether this remains a data-theft and exposure incident, or whether the leaked credentials and claimed access become part of a second phase. For a water provider, even an unconfirmed disruption claim can damage trust. A confirmed lateral path between technical platforms and billing systems would raise harder questions about segmentation, monitoring, and how quickly Cal Water can prove the attacker is out.

Impact Analysis

  • The alleged breach exposed sensitive customer and internal utility data tied to a major California water provider.
  • Claims of access near operational systems raise concern even though OT/ICS disruption has not been confirmed.
  • The incident highlights how geopolitical cyber activity can target critical infrastructure providers.

Cal Water Service Footprint

Customers served
count2,000,000
Communities served
count100
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Cyber security concept shown on grunge-style background highlights the importance of digital protection.Cybersecurity

Iran Cyberattack Shuts UK Power Plant Amid US Sanctions

US sanctions target six Iranian hackers following a destructive cyberattack that forced a UK power plant offline for four days, signaling a sharp escalation aga

Aug 25, 20264 min
New York water facility protected by cybersecurity shields and digital network overlaysCybersecurity

New York Water Cybersecurity Grants Shield 153 Utilities

New York is spending $9M to harden 153 water systems, but the grants buy targeted fixes, not full cyber resilience.

Aug 4, 20267 min
Wooden letter blocks spelling 'CYBER SECURITY' on a wooden grid background for data protection themes.Cybersecurity

100 Cities Lose Control of Water Supply in Cyber Siege

Over 100 U.S. water systems were directly targeted and breached in a single month, as hackers sabotaged industrial hardware controlling the water supply, forcin

Aug 27, 20266 min
Close-up view of a mouse cursor over digital security text on display.Cybersecurity

U.S. Charges Iran in Multi-Billion Dollar Hacking Heist

U.S. prosecutors charged 17 Iranians with stealing over $3 billion in intellectual property from American universities and companies for Iran's Revolutionary Gu

Aug 19, 20265 min
Minnesota water utility facility under cyberattack with digital shields, locks, and dark data network visuals.Cybersecurity

30 Minnesota Water Systems Rattled by Cyberattacks

More than 30 Minnesota water systems were hit in two days, exposing weak utility defenses as officials warn about Iranian hackers.

Aug 1, 202611 min
Truck refueling at dusk as diesel pump prices hit all-time high, with market data reflections.Trading

Diesel Hits Historic High in U.S., Vetoing Iran War Message

U.S. diesel prices have surged to an all-time high of $5.85 a gallon, a direct economic blow from the Iran conflict hitting voters just weeks before midterm ele

Sep 6, 20268 min
A futuristic AI interface in a sleek supermarket hub, visualizing chat prompts being translated dynamically into a digital grocery cart.Technology

Instacart Ends Grocery Scrolling With AI Concierge Clementine

Instacart released Clementine, an AI assistant that turns casual chat prompts like 'kid lunches for a week' into a fully built, ready-to-checkout grocery order.

Sep 9, 20268 min
A stressed couple in a modern apartment reviews a bank app overdraft alert, a discarded coffee cup nearby, illustrating financial strain.Fintech

Deep Cuts Destroy Paycheck-to-Paycheck Budgets

Living paycheck to paycheck is no longer about trimming small luxuries. Once those are gone, families face cuts with generational consequences.

Sep 9, 20267 min
A dynamic forex trading floor scene showing intense focus on a glowing EUR/USD chart at a critical technical level.Trading

Euro Hits Multi-Year Wall in ECB Showdown

The euro's rally hit a brick wall at the 200-day moving average, setting up a decisive showdown with Thursday's European Central Bank monetary policy meeting.

Sep 9, 20266 min
Hurricane winds and torrential rain batter tropical coastline, illustrating infrastructure vulnerability during extreme weather events.Global Trends

Hurricane Lowell Cuts Power to 30,000 on Kauai

Hurricane Lowell's offshore winds knocked out power for 30,000 residents on Kauai, showcasing how vulnerable critical infrastructure is even without a direct la

Sep 9, 20268 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.