Cyber Incident Victim: California Water Service
Timeline
Summary
California Water Service investigated a cyber attack claimed by an Iranian-linked hacker group and found that threat actors accessed one active customer’s online account using stolen credentials and also reached an external third‑party GPS correction tool website, while no internal IT or operational technology systems were compromised and no payment information was exposed. The utility said its cybersecurity response, supported by Mandiant and government partners, uncovered no evidence of activity in its internal networks, and the group Handala stated the intrusion was a warning related to U.S. strikes in Iran and that it deliberately avoided disrupting water delivery.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On June 11, 2026, the Iranian-linked hacker group Handala claimed responsibility for a cyber attack on California Water Service, stating that the intrusion was a warning to the federal government after U.S. air strikes damaged water resources in Sirik, Iran two days earlier. Handala asserted that it had accessed several Cal Water facilities in Bakersfield, Visalia and Chico and shared screenshots purporting to show residents’ bills, while also claiming to have exfiltrated five gigabytes of data from the utility. The group said it could have disrupted water treatment or distribution but chose not to do so. In a blog post on June 12, Handala described the attack as retaliation for recent U.S. actions in Iran and said it had the ability to cut off water access but refrained. Threat intelligence company Dataminr reported that the group likely gained initial access through Cal Water’s RTKBase instance, a GNSS base station platform, and then moved laterally to a billing system. Dataminr also noted that the RTKBase instance had been operating for approximately 783 continuous hours at the time of the intrusion, with GPS correction data streamed across seven district mountpoints.

California Water Service responded by activating its cybersecurity response plan and working around the clock with state and federal agencies as well as external experts, including Mandiant, a subsidiary of Google Cloud. The company conducted a preliminary scan of its internal IT and OT networks and reported no signs of compromise in water production or delivery systems. Mandiant’s investigation found no evidence of threat actor activity in Cal Water’s internal technology or operational technology environments. Instead, the investigation determined that the unauthorized activity was limited to a small number of specific user accounts within two third‑party service provider platforms. One active customer’s online Cal Water account was accessed using stolen credentials, but that account did not provide entry to the billing system and no payment information was compromised. The threat actor also visited an external third‑party website related to a GPS location correction tool, which contained no confidential or sensitive information.
Despite Handala’s claims of a five‑gigabyte data dump, Cal Water stated that the accessed customer account did not yield billing or payment data. The alleged dump, according to Handala and Dataminr, contained personally identifiable information such as names, addresses, phone numbers, account numbers and payment histories, as well as administrative credentials for the RTKBase platform and a mountpoint‑level NTRIP source password. Dataminr observed that the threat actor performed enumeration of IP addresses associated with Cal Water’s NTRIP network across seven districts and noted that the group’s toolkit includes custom wipers and MBR‑overwriting capabilities. No disruption to OT/ICS systems was confirmed by either Cal Water or the investigating cybersecurity firms. Cal Water serves roughly two million customers across one hundred communities in California, and Dataminr identified the Chico District as the victim of the attack. On June 15, Cal Water told SecurityWeek that it was continuing to investigate the hacking claims.
