Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
South Staffordshire Water traced a phishing-enabled compromise to September 2020, followed by major network activity and discovery in July 2022. [1][2]
Impact
Exfiltration and later dark-web publication of customer and employee personal information. [1]
Documented data types include:
- Names — Full names. [1]
- Gender information — Gender information. [1]
- Disability and special-education information — Information from which disabilities could be inferred for a small percentage of Priority Services Register customers. [1]
- National Insurance numbers — National Insurance numbers in employee HR information. [1]
- Account credentials — South Staffordshire Water online-service usernames and passwords for customers. [1]
- Dates of birth — Dates of birth. [1]
- Financial account information — Customer bank-account numbers and sort codes. [1]
- Contact information — Physical addresses, email addresses, and telephone numbers. [1]
A cited record reports 633,887 individuals (People whose personal information the ICO says was published on the dark web in August 2022). [1]
Between August and November 2022, South Staffordshire detected that more than 4.1 terabytes of data had been published on the dark web. [1]
Timeline
Discovery
Date an internal investigation began after IT performance issues.
[1]Documented event
Date South Staffordshire reported the personal data incident to the ICO.
[1]Documented event
Date of the final monetary penalty notice.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
A successful phishing email led a recipient to open an attachment that enabled installation of malicious software. [1]
In May 2022, the attacker moved through the network and compromised domain-administrator privileges. [1]
The ICO found inadequate vulnerability management, including unpatched critical systems and no regular internal or external security scans. [1]
The ICO found that limited controls allowed privilege escalation after the initial network foothold. [1]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
Response
The final penalty reflected a 40% reduction after an early admission; South Staffordshire agreed to pay without appeal. The ICO found inadequate monitoring and logging, with only 5% of the IT environment monitored. South Staffordshire discovered an unsuccessfully distributed ransom note on 26 July 2022. Initial access was traced to September 2020 and remained undetected for approximately 20 months. The ICO found obsolete and unsupported software on some devices, including Windows Server 2003. The ICO imposed a £963,900 monetary penalty for infringements of UK GDPR Articles 5(1)(f) and 32(1). No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]
