logo

UK water company allowed hackers to lurk undetected for nearly two years, regulator finds

ID: 7f2472c9-a7c5-580e-8337-2f11578b9708

STIX ID: report--7f2472c9-a7c5-580e-8337-2f11578b9708

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

...
...

A Cl0p ransomware-related intrusion into South Staffordshire Water began with a malicious email in September 2020 and, after exploiting the critical ZeroLogon vulnerability and using a domain administrator account for lateral movement, resulted in the publication of ~4.1 TB of personal data affecting 633,887 people; the ICO fined the company £963,900 for failures including inadequate privilege controls, incomplete monitoring, unpatched systems, and lack of vulnerability scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.