Two-Year Hidden Intrusion Exposed Water Sector Detection Gaps

The real failure here is not the ransom note. A domain-admin-level intruder stayed inside a water utility for 21 months, and the breach only surfaced because IT performance slowed down, which means routine monitoring never flagged a full compromise already in progress. The ICO says South Staffordshire Water was first reached through a malicious email attachment in September 2020, then remained undetected until July 2022. The attacker later moved laterally using a domain administrator account, and personal data from 633,887 customers and employees was published in August 2022; the regulator fined the company £963,900. The lasting risk is the gap between initial foothold and detection. For critical-infrastructure operators, this is a warning that access control and alerting failures can let one phishing event turn into long-lived control of internal systems and data.

Part of the PlainSec briefing for 2026-05-12

Sources