Breaches · 125 days ago
The real failure here is not the ransom note. A domain-admin-level intruder stayed inside a water utility for 21 months, and the breach only surfaced because IT performance slowed down, which means routine monitoring never flagged a full compromise already in progress.
The ICO says South Staffordshire Water was first reached through a malicious email attachment in September 2020, then remained undetected until July 2022. The attacker later moved laterally using a domain administrator account, and personal data from 633,887 customers and employees was published in August 2022; the regulator fined the company £963,900.
The lasting risk is the gap between initial foothold and detection. For critical-infrastructure operators, this is a warning that access control and alerting failures can let one phishing event turn into long-lived control of internal systems and data.
5 sources covering this story
UK fines water supplier $1.3M for exposing data of 664k customers
The Information Commissioner's Office has fined South Staffordshire Water Plc and parent company South Staffordshire Plc £963,900 ($1.3 million) over a cyberattack that exposed the personal data of 663,887 customers and employees.
UK ICO fines South Staffordshire Water nearly £1M over Cl0p breach, signals tougher utility cyber defense oversight.
South Staffordshire Water Fined £1m After Data Breach
The ICO has fined South Staffordshire Water nearly £1m for a series of data protection failings
Poor security left hackers inside water company network for nearly two years - Help Net Security
The UK ICO fined South Staffordshire Water’s parent company £963,900 after a phishing attack exposed data belonging to 633,887 people.
The Record from Recorded Future
UK water company allowed hackers to lurk undetected for nearly two years, regulator finds
The Information Commissioner's Office (ICO) fined South Staffordshire Water £963,900 ($1.3 million) on Monday over an attack by the Cl0p ransomware group that led to the personal data of 633,887 customers and employees being published in August 2022.
Part of the PlainSec briefing for 2026-05-12