---
title: "South Staffordshire cyberattack and data incident"
description: "Evidence-backed account of South Staffordshire cyberattack and data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/south-staffordshire-cyberattack-data-incident-2020"
markdown_url: "https://www.ally.security/incidents/south-staffordshire-cyberattack-data-incident-2020.md"
stix_url: "https://www.ally.security/incidents/south-staffordshire-cyberattack-data-incident-2020/stix.json"
---

# South Staffordshire cyberattack and data incident

Phishing-enabled compromise traced to September 2020, followed by major network activity and discovery in July 2022. Exfiltration and later dark-web publication of customer and employee personal information.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

[South Staffordshire Water](https://www.south-staffs-water.co.uk/) traced a phishing-enabled compromise to September 2020, followed by major network activity and discovery in July 2022. [1](#source-1) [2](#source-2)

## Impact

Exfiltration and later dark-web publication of customer and employee personal information. [1](#source-1)

Documented data types include:

- Names — Full names. [1](#source-1)
- Gender information — Gender information. [1](#source-1)
- Disability and special-education information — Information from which disabilities could be inferred for a small percentage of Priority Services Register customers. [1](#source-1)
- National Insurance numbers — National Insurance numbers in employee HR information. [1](#source-1)
- Account credentials — South Staffordshire Water online-service usernames and passwords for customers. [1](#source-1)
- Dates of birth — Dates of birth. [1](#source-1)
- Financial account information — Customer bank-account numbers and sort codes. [1](#source-1)
- Contact information — Physical addresses, email addresses, and telephone numbers. [1](#source-1)

A cited record reports 633,887 individuals (People whose personal information the ICO says was published on the dark web in August 2022). [1](#source-1)

Between August and November 2022, South Staffordshire detected that more than 4.1 terabytes of data had been published on the dark web. [1](#source-1)

## Timeline

### July 15, 2022 — Discovery

Date an internal investigation began after IT performance issues. [1](#source-1)

### July 24, 2022 — Documented event

Date South Staffordshire reported the personal data incident to the ICO. [1](#source-1)

### May 7, 2026 — Documented event

Date of the final monetary penalty notice. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

A successful phishing email led a recipient to open an attachment that enabled installation of malicious software. [1](#source-1)

In May 2022, the attacker moved through the network and compromised domain-administrator privileges. [1](#source-1)

The ICO found inadequate vulnerability management, including unpatched critical systems and no regular internal or external security scans. [1](#source-1)

The ICO found that limited controls allowed privilege escalation after the initial network foothold. [1](#source-1)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- [T1566.001 — Phishing: Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001/) [1](#source-1)
- [T1204.002 — User Execution: Malicious File](https://attack.mitre.org/techniques/T1204/002/) [1](#source-1)

## Response

The final penalty reflected a 40% reduction after an early admission; South Staffordshire agreed to pay without appeal. The ICO found inadequate monitoring and logging, with only 5% of the IT environment monitored. South Staffordshire discovered an unsuccessfully distributed ransom note on 26 July 2022. Initial access was traced to September 2020 and remained undetected for approximately 20 months. The ICO found obsolete and unsupported software on some devices, including Windows Server 2003. The ICO imposed a £963,900 monetary penalty for infringements of UK GDPR Articles 5(1)(f) and 32(1). No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/south-staffordshire-cyberattack-data-incident-2020/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Fine of nearly £1m issued against South Staffordshire following major cyber attack and data breach

regulatory · Information Commissioner's Office · May 11, 2026

<https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/05/fine-of-nearly-1m-issued-against-south-staffordshire-plc-and-south-staffordshire-water-plc/>

<a id="source-2"></a>

### South Staffordshire Plc and South Staffordshire Water Plc

regulatory · Information Commissioner's Office · May 7, 2026

<https://ico.org.uk/action-weve-taken/enforcement/2026/05/south-staffordshire-plc-and-south-staffordshire-water-plc/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: A successful phishing email led a recipient to open an attachment that enabled installation of malicious software.
2. **Affected Organization · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: South Staffordshire Plc
3. **Affected Organization · 100% confidence · current**  
   ICO South Staffordshire monetary penalty: South Staffordshire Plc
4. **Exposed Data Category · 100% confidence · current**  
   South Staffordshire customer and employee data exposure: Names
5. **Resulted In · 100% confidence · current**  
   ICO South Staffordshire monetary penalty: The final penalty reflected a 40% reduction after an early admission; South Staffordshire agreed to pay without appeal.
6. **Discovered At · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: 2022-07-15
7. **Exposed Data Category · 100% confidence · current**  
   South Staffordshire customer and employee data exposure: Gender information
8. **Resulted In · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: In May 2022, the attacker moved through the network and compromised domain-administrator privileges.
9. **Resulted In · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: The ICO found inadequate monitoring and logging, with only 5% of the IT environment monitored.
10. **Exposed Data Category · 100% confidence · current**  
   South Staffordshire customer and employee data exposure: Disability and special-education information
11. **Resulted In · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: South Staffordshire customer and employee data exposure
12. **Exposed Data Category · 100% confidence · current**  
   South Staffordshire customer and employee data exposure: National Insurance numbers
13. **Resulted In · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: The ICO found inadequate vulnerability management, including unpatched critical systems and no regular internal or external security scans.
14. **Occurred At · 100% confidence · current**  
   South Staffordshire report to the ICO: 2022-07-24
15. **Located In · 100% confidence · current**  
   South Staffordshire customer and employee data exposure: United Kingdom
16. **Affected Organization · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: South Staffordshire Water Plc
17. **Subsidiary Of · 100% confidence · current**  
   South Staffordshire Water Plc: South Staffordshire Plc
18. **Exposed Data Category · 100% confidence · current**  
   South Staffordshire customer and employee data exposure: Account credentials
19. **Exposed Data Category · 100% confidence · current**  
   South Staffordshire customer and employee data exposure: Dates of birth
20. **Resulted In · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: South Staffordshire discovered an unsuccessfully distributed ransom note on 26 July 2022.
21. **Used Attack Technique · 95% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: https://attack.mitre.org/techniques/T1566/001/
22. **Resulted In · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: The ICO found that limited controls allowed privilege escalation after the initial network foothold.
23. **Occurred At · 100% confidence · current**  
   ICO South Staffordshire monetary penalty: 2026-05-07
24. **Resulted In · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: Initial access was traced to September 2020 and remained undetected for approximately 20 months.
25. **Affected Individual Count · 100% confidence · current**  
   South Staffordshire customer and employee data exposure: 633,887 individual
26. **Used Attack Technique · 95% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: https://attack.mitre.org/techniques/T1204/002/
27. **Exposed Data Category · 100% confidence · current**  
   South Staffordshire customer and employee data exposure: Financial account information
28. **Affected Organization · 100% confidence · current**  
   ICO South Staffordshire monetary penalty: South Staffordshire Water Plc
29. **Resulted In · 100% confidence · current**  
   South Staffordshire customer and employee data exposure: Between August and November 2022, South Staffordshire detected that more than 4.1 terabytes of data had been published on the dark web.
30. **Exposed Data Category · 100% confidence · current**  
   South Staffordshire customer and employee data exposure: Contact information
31. **Resulted In · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: The ICO found obsolete and unsupported software on some devices, including Windows Server 2003.
32. **Resulted In · 100% confidence · current**  
   ICO South Staffordshire monetary penalty: The ICO imposed a £963,900 monetary penalty for infringements of UK GDPR Articles 5(1)(f) and 32(1).
33. **Resulted In · 100% confidence · current**  
   South Staffordshire 2020–2022 cyberattack: South Staffordshire report to the ICO

</details>
