Digital

ICO fines South Staffordshire Water nearly £1 million after cyber attack

ICO fines South Staffordshire Water nearly £1 million after cyber attack

The UK Information Commissioner's Office (ICO) has fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 following a cyber attack that resulted in the personal information of 633,887 customers and employees being extracted and later published on the dark web.

According to the ICO, the intrusion can be traced back to September 2020, when a member of staff opened a phishing email attachment that allowed an attacker to install malicious software on the company's network. The software remained undetected for 20 months. In May 2022, the attacker moved through the network and obtained domain administrator privileges. The bulk of the attack took place between May and July 2022.

The breach was identified on 15 July 2022, when IT performance issues prompted an internal investigation. South Staffordshire reported the personal data breach to the ICO on 24 July 2022. Two days later, the company discovered a ransom note that the attacker had unsuccessfully attempted to distribute to staff. Between August and November 2022, the company detected that more than 4.1 terabytes of data had been published on the dark web.

In May 2022, the attacker moved through the network and obtained domain administrator privileges

At the time of the attack, South Staffordshire held personal information on approximately 1.85 million customers, about 750,000 current and 1.1 million former, along with 2,791 current and at least 2,298 former employees. The data later published on the dark web included names, addresses, email addresses, dates of birth, gender and telephone numbers. For employees, HR information including National Insurance numbers was exposed. For customers, account credentials for South Staffordshire Water online services as well as bank account numbers and sort codes were leaked. A small percentage of customers on the Priority Services Register also had information published from which disabilities could be inferred.

The ICO's investigation found that the company had failed to implement appropriate security controls required under UK data protection law. Limited controls allowed the attacker to escalate to administrator privileges after gaining a foothold on the network. Only 5% of the IT environment was being monitored, meaning malicious activity went undetected. Some devices were running obsolete, unsupported software, including Windows Server 2003. Vulnerability management was also inadequate, with unpatched critical systems and no regular internal or external security scans.

"Customers do not have the choice over which water company serves them;  they are required to share their personal information and place their trust in that provider. It is therefore essential that water companies honour that trust by taking their data protection responsibilities seriously," said Ian Hulme, ICO Interim Executive Director for Regulatory Supervision. "The steps that South Staffordshire failed to take are established, widely understood and effective controls to protect computer networks. Waiting for performance issues or a ransom note to discover a breach is not acceptable. Proactive security is a legal requirement, not an optional extra."

The ICO is urging organisations to review their cyber resilience in light of the case, asking whether access controls limit users and systems to what they genuinely need, whether logging and monitoring provide adequate coverage and alerts are acted upon, whether all systems are patched and supported, and whether vulnerability management, including both internal and external scanning, is part of regular operational practice.

 

Follow us on Google Discover