← South Staffordshire Water

2020 South Staffordshire Water — phishing breach; 633,887 exposed after 20 months undetected (ICO fine May 2026)

2020 633.9K records affected Share on X

Data compromised

Names, addresses, emails, DOB, phones; customer portal usernames/passwords; bank details; employee NI numbers; Priority Services Register data for some customers

Technical writeup

South Staffordshire Plc and South Staffordshire Water Plc (South Staffs Water) suffered a cyber attack beginning with a successful phishing email in September 2020 that installed malicious software remaining undetected for 20 months. The UK Information Commissioner's Office (ICO) said the attacker escalated to domain administrator privileges in May 2022; the company identified the breach after IT performance issues prompted investigation on 15 July 2022 and reported to the ICO on 24 July 2022. Between August and November 2022, more than 4.1 terabytes of data—including personal details, customer online-service credentials, bank account numbers and sort codes, and employee National Insurance numbers—was published on the dark web, affecting 633,887 people. On 11 May 2026 the ICO fined the group £963,900 after a voluntary settlement with early admission of liability; failures cited included inadequate monitoring (only ~5% of the IT environment logged), obsolete software such as Windows Server 2003, and weak privilege controls. Renewed May 2026 reporting highlighted long-tail identity fraud and scam fallout for victims years after the intrusion.

Root cause

Phishing email with malicious attachment; 20-month undetected malware; domain admin compromise; inadequate monitoring and patching

References