logo

UK fines water supplier $1.3M for exposing data of 664k customers

ID: 765c6f6d-d31d-52f4-a183-c2606005d74f

STIX ID: report--765c6f6d-d31d-52f4-a183-c2606005d74f

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Bill Toulas

...
...

The UK Information Commissioner fined South Staffordshire Water £963,900 after a phishing-enabled malware intrusion—initially traced back to September 2020 and active May–July 2022—exposed personal data for approximately 663,887 customers and employees (names, addresses, emails, DOBs, account credentials, bank details, National Insurance numbers). The attackers escalated privileges to domain administrator and remained undetected for about 20 months; the ICO cited failures including insufficient privilege controls, monitoring covering only ~5% of the environment, obsolete software (Windows Server 2003), missing patches, and lack of regular security scans, and reduced the fine due to early admission and cooperation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.