ICO Fines South Staffordshire Water
Coverage from The Record, ComputerWeekly.com, and others

The UK Information Commissioner’s Office fined South Staffordshire Plc and South Staffordshire Water Plc about £964,000 after a cyberattack exposed the personal data of more than 633,000 customers and employees.
The intrusion began with phishing in 2020, remained undetected for nearly two years, and involved privilege escalation, inadequate monitoring, obsolete software, and unpatched systems before data was published on the dark web. The case highlights regulatory scrutiny of cybersecurity controls at water providers and the consequences of delayed breach detection.
The update adds specificity to the intrusion mechanics, including the likely use of a phishing attachment, privilege escalation via ZeroLogon, and the addition of Cl0p as the reported threat actor. It also slightly reframes the case from a broad privacy enforcement story to one emphasizing delayed detection and control failures at a water provider.
The update materially sharpens the scale and specifics of the breach: it now identifies both South Staffordshire Plc and its water subsidiary as penalized parties, and says more than 633,000 people were affected by data published on the dark web. It also adds a stronger account of the security failures, including missing vulnerability scanning, unpatched systems and obsolete Windows Server 2003.
