
California Water Service Ransomware: Handala Claims 5GB Data Leak (June 2024)
California Water Service: What Happened
On June 2024, the Iran-linked threat actor Handala claimed responsibility for a ransomware attack targeting California Water Service (Cal Water). The group publicly asserted they had exfiltrated and leaked 5GB of sensitive data, including customer personal information and administrative credentials for the RTKBase GNSS base station platform. The breach reportedly began with the compromise of the RTKBase platform, followed by lateral movement into Cal Water's billing system. At this time, there is no confirmation of operational technology (OT) or industrial control system (ICS) disruption, but the risk of service disruption remains a concern.
Attack Vector & Technical Detail
Initial access was achieved through the RTKBase GNSS base station platform, a critical component in Cal Water's infrastructure. While no specific CVEs or IOCs have been disclosed, the attack demonstrated the use of MITRE ATT&CK tactics TA0001 (Initial Access), TA0008 (Lateral Movement), and TA0005 (Defense Evasion). The attackers leveraged compromised administrative credentials to escalate privileges and move laterally into the billing environment, exfiltrating data before deploying ransomware. The leak was subsequently advertised on the PrinzEugen leak site (Tor), signaling intent to pressure the victim and maximize impact.
Confirmed Impact
The breach resulted in the exposure of personally identifiable information (PII) such as customer names, addresses, phone numbers, account numbers, and payment histories. Additionally, administrative credentials for the RTKBase platform were compromised. The affected region is North America, specifically California. While no direct evidence of OT/ICS disruption has been reported, the exposure of credentials and sensitive data introduces regulatory risks, including potential violations of state and federal data protection laws. Immediate credential rotation and a comprehensive audit of the RTKBase instance are required to mitigate ongoing risk.
What This Means for Your Organization
This incident underscores the vulnerability of third-party platforms and the risk of lateral movement from IT to sensitive operational environments. Organizations relying on platforms like RTKBase should prioritize credential hygiene, network segmentation, and continuous monitoring for anomalous access patterns. Regular audits of privileged accounts and rapid credential rotation are critical to reducing dwell time and limiting attacker movement. Proactive defense against ransomware groups with nation-state affiliations is essential, given their demonstrated capability to target critical infrastructure.
Detection & Response
- Immediate: Rotate all administrative credentials for RTKBase and affected billing systems; take RTKBase instance offline for forensic review.
- Hunt: Search for unauthorized access to RTKBase, suspicious lateral movement, and data exfiltration consistent with MITRE tactics TA0001, TA0008, TA0005.
- Patch: N/A (no specific CVE disclosed).
Source: https://www.securityweek.com/iranian-cyber-group-handala-claims-cal-water-hack/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

