Last Update: 08/01/2026 at 1:00 PM EST

ICO Fines South Staffordshire Water

Coverage from BleepingComputer, ComputerWeekly.com, and others

Articles

4

Active Days

5

The Topic

ICO Fines South Staffordshire Water topic image

The UK Information Commissioner’s Office fined South Staffordshire Plc and South Staffordshire Water Plc about £964,000 after a cyberattack exposed the personal data of more than 633,000 customers and employees. The intrusion began with phishing in 2020, remained undetected for nearly two years, and involved privilege escalation, inadequate monitoring, obsolete software, and unpatched systems before data was published on the dark web. The case highlights regulatory scrutiny of cybersecurity controls at water providers and the consequences of delayed breach detection.

First Article: 05/11/26

Latest Article: 05/15/26

Summary

  • The ICO fined South Staffordshire Plc and South Staffordshire Water Plc approximately £964,000.
  • Personal data for more than 633,000 customers and employees was extracted and published on the dark web.
  • The intrusion began with a phishing email or attachment in September 2020 and went undetected until July 2022.
  • Attackers obtained domain administrator access and exploited weak access controls, inadequate monitoring, obsolete software, and unpatched systems.
  • The exposed information included contact details, dates of birth, account credentials, bank data, and employee National Insurance numbers.
  • The penalty was reduced by 40% after early admission of liability, cooperation, mitigation, and a voluntary settlement.
  • Reporting does not indicate that water treatment or supply operations were compromised.

History

07/23/2026

The update adds specificity to the intrusion mechanics, including the likely use of a phishing attachment, privilege escalation via ZeroLogon, and the addition of Cl0p as the reported threat actor. It also slightly reframes the case from a broad privacy enforcement story to one emphasizing delayed detection and control failures at a water provider.

07/22/2026

The update materially sharpens the scale and specifics of the breach: it now identifies both South Staffordshire Plc and its water subsidiary as penalized parties, and says more than 633,000 people were affected by data published on the dark web. It also adds a stronger account of the security failures, including missing vulnerability scanning, unpatched systems and obsolete Windows Server 2003.

Featured

Timeline: 5 Days

May 11May 12May 13May 14May 15

Additional Articles

⭐⭐⭐

Global Relay Intelligence & Practice05-15-2026
The UK information regulator fined South Staffordshire Plc and South Staffordshire Water Plc for a cyber attack in which personal data of 633887 people was compromised between 2020 and 2022 and published on the dark web.