South Staffordshire Water has been fined £963,900 (approximately $1.3 million) by the Information Commissioner’s Office (ICO) for a cyberattack that exposed the personal data of 663,887 customers and employees. The water company, which serves 1.6 million consumers daily with 330 million litres of drinking water, was the target of a widespread cyberattack that went undetected for almost two years. The case highlights the serious consequences that inadequate cybersecurity can have for critical infrastructure providers.
See also: Fortnite and South Park: New crossover and Quints playlist

The attack began in September 2020 via a phishing email that allowed attackers to install malware on the company’s systems. The malware remained hidden for 20 months, while the hackers managed to escalate their privileges and gain domain administrator access between May and July 2022. The breach was only discovered in July 2022, when IT system performance issues led to an investigation. The long duration of the attackers’ presence on the network indicates serious shortcomings in the company’s detection and monitoring capabilities.
The leaked data included full names, physical addresses, email addresses, telephone numbers, dates of birth, customer account credentials, bank account details and employee HR data including National Insurance numbers. The Cl0p ransomware group claimed responsibility for the attack, although South Staffordshire Water initially disputed their claims. The exposure of such sensitive personal and financial data puts victims at risk of identity theft and financial fraud for years.
See also: Southern Water: Black Basta ransomware attack cost £4.5m

Technical recommendations to strengthen cybersecurity
To prevent similar incidents, organizations must implement comprehensive cybersecurity strategies. Adopting multi-factor authentication (MFA) on all critical systems can significantly prevent privilege escalation even after a successful phishing attack. Implementing a zero-trust architecture with a “never trust, always verify” principle ensures that every access request is verified regardless of its origin.
Network monitoring should cover 100% of the IT environment, not just 5% as in the case of South Staffordshire Water. The use of SIEM (Security Information and Event Management) systems and EDR (Endpoint Detection and Response) tools can detect suspicious activity in real time. In addition, regular penetration testing and red team exercises help identify vulnerabilities before malicious actors exploit them.
The South Staffordshire Water case highlights the risks critical infrastructure providers face from advanced persistent threats. The fact that the malware remained undetected for 20 months highlights the need for improved threat monitoring and detection capabilities. Critical infrastructure companies must adopt a zero-trust architecture and implement continuous monitoring across their entire network. Network segmentation between operational technology (OT) and information technology (IT) systems is critical to protecting critical water supply operations.
See also: Southern Water – data breach: Black Basta ransomware gang leaked data

The use of outdated operating systems such as Windows Server 2003 is a significant security risk that must be addressed immediately. Organizations should develop comprehensive patch management programs and conduct regular vulnerability assessments. Establishing a 24/7 Security Operations Center (SOC) with specialized personnel can ensure continuous monitoring and immediate response to security incidents.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
