Last Update: 09/22/2026 at 11:34 PM EST

ICO Fines South Staffordshire Water

Coverage from The Record, ComputerWeekly.com, and others

ICO Fines South Staffordshire Water topic image

The UK Information Commissioner’s Office fined South Staffordshire Plc and South Staffordshire Water Plc about £964,000 after a cyberattack exposed the personal data of more than 633,000 customers and employees.

The intrusion began with phishing in 2020, remained undetected for nearly two years, and involved privilege escalation, inadequate monitoring, obsolete software, and unpatched systems before data was published on the dark web. The case highlights regulatory scrutiny of cybersecurity controls at water providers and the consequences of delayed breach detection.

Looking Back
5 Day Timeline
May 11May 12May 13May 14May 15
History
07/23/2026

The update adds specificity to the intrusion mechanics, including the likely use of a phishing attachment, privilege escalation via ZeroLogon, and the addition of Cl0p as the reported threat actor. It also slightly reframes the case from a broad privacy enforcement story to one emphasizing delayed detection and control failures at a water provider.

07/22/2026

The update materially sharpens the scale and specifics of the breach: it now identifies both South Staffordshire Plc and its water subsidiary as penalized parties, and says more than 633,000 people were affected by data published on the dark web. It also adds a stronger account of the security failures, including missing vulnerability scanning, unpatched systems and obsolete Windows Server 2003.

All Articles4 articles
Additional4 articles · CI Score below 45
The Record / Alexander Martin
5/11/2026 • Data Breaches & Exposure Events • General
ComputerWeekly.com
5/11/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Bill Toulas
5/12/2026 • Data Breaches & Exposure Events • General
Global Relay Intelligence & Practice
5/15/2026 • Data Breaches & Exposure Events • General