DailyGlimpse

Water firm fined after customers' details hacked

Business
May 13, 2026 · 1:38 AM
Water firm fined after customers' details hacked

South Staffordshire Water fined after customers' details hacked

Skip to content

Advertisement

Watch Live

Subscribe

Sign In

Home

News

Sport

Business

Technology

Health

Culture

Arts

Travel

Earth

Audio

Video

Live

Documentaries

Weather

Newsletters

Watch Live

Advertisement

Water firm fined after customers' details hacked

14 hours ago

Share

Save

Add as preferred on Google

Oprah Flash West Midlands

BBC

The hack went undetected by the firm for 20 months, regulators found

A water company has been fined after hundreds of thousands of customers had their personal data hacked.

South Staffordshire, made up of South Staffordshire Plc and South Staffordshire Water Plc, was ordered to pay £963,900 by the Information Commissioner's Office (ICO) following the cyber attack, traced back to September 2020.

The firm supplies south Staffordshire, parts of the Black Country and surrounding areas.

Personal information of 633,887 people was taken and published on the dark web in the attack, which largely took place between May and July 2022, the ICO found.

The watchdog and water company agreed a voluntary settlement and South Staffordshire made an early admission of liability, agreeing to pay the penalty without appeal.

A phishing email was used to launch the hack which allowed the cyber attackers to install malicious software and it remained undetected within the organisation's systems for 20 months.

In May 2022, the hacker went through the firm's network and took over administrator privileges — the highest level of system access to the IT network, the ICO said.

Advertisement

Ransom note

The breach came to light when IT performance issues prompted an internal investigation on 15 July 2022.

The company reported a personal data breach a few days later before, on 26 July 2022, South Staffordshire found a ransom note that the hacker had unsuccessfully attempted to send to certain members of staff.

Between August and November 2022, South Staffordshire discovered more than 4.1 terabytes (TB, each equal to 1,000GB) of data were published on the dark web.

They included bank details of customers and National Insurance numbers of staff.

The ICO's investigation found South Staffordshire failed to bring in adequate security controls under UK data protection law, which allowed the hackers to get administrator access.

They were also allowed to operate largely undetected due to minimal monitoring of their activities, the use of obsolete systems by the firm and take advantage of failures including a lack of regular security scans.

Ian Hulme, from the ICO, said: "Waiting for performance issues or a ransom note to discover a breach is not acceptable. Proactive security is a legal requirement, not an optional extra."

Follow BBC Stoke & Staffordshire onBBC Sounds,Facebook,XandInstagram.

More on this story

'Worrying precedent' as hackers target water firm

Water customers' bank details may have been leaked

Hack leaves water customers feeling vulnerable

Related internet links

Information Commissioner's Office

South Staffordshire Water

Coventry & Warwickshire

Derby


Related

'Aladdin's cave' of stolen plant machinery seized

Special needs focus at boxer's 'dream' gym

'No-confidence vote worked in our favour' - Reform


More from the BBC

10 hrs ago ## Nine-year-old remembered by fellow pupils Nine-year-old Brody Price died from a rare brain tumour. 10 hrs ago

21 hrs ago ## Council voting on funds to boost new rail HQ plans Cabinet will consider an investment partnership with the East Midlands Combined County Authority (EMCCA). 21 hrs ago

2 days ago ## Assembly Rooms redevelopment plan set to be decided According to council documents, the proposed redevelopment could cost £100m. 2 days ago

4 days ago ## Former pub and nightclub could become jazz venue There are plans to open a new jazz club in the Grade II-listed building. 4 days ago

5 days ago ## Snapchat 'monster' abused more than 150 children Siah Riley posed as a teenager to blackmail young victims into sending him explicit content. 5 days ago


BBC in other languages

The BBC is in multiple languages

Read the BBC In your own language

Oduu Afaan Oromootiin

Amharic ዜና በአማርኛ

Arabic عربي

Azeri AZƏRBAYCAN

Bangla বাংলা

Burmese မြန်မာ

Chinese 中文网

Dari دری

French AFRIQUE

Hausa HAUSA

Hindi हिन्दी

Gaelic NAIDHEACHDAN

Gujarati ગુજરાતીમાં સમાચાર

Igbo AKỤKỌ N’IGBO

Indonesian INDONESIA

Japanese 日本語

Kinyarwanda GAHUZA

Kirundi KIRUNDI

Korean 한국어

Kyrgyz Кыргыз

Marathi मराठी

Nepali नेपाली

Noticias para hispanoparlantes

Pashto پښتو

Persian فارسی

Pidgin

Polish PO POLSKU

Portuguese BRASIL

Punjabi ਪੰਜਾਬੀ ਖ਼ਬਰਾਂ

Russian НА РУССКОМ

Serbian NA SRPSKOM

Sinhala සිංහල

Somali SOMALI

Swahili HABARI KWA KISWAHILI

Tamil தமிழில் செய்திகள்

Telugu తెలుగు వార్తలు

Thai ข่าวภาษาไทย

Tigrinya ዜና ብትግርኛ

Turkish TÜRKÇE

Ukrainian УКРАЇНСЬКA

Urdu اردو

Uzbek O'ZBEK

Vietnamese TIẾNG VIỆT

Welsh NEWYDDION

Yoruba ÌRÒYÌN NÍ YORÙBÁ

Follow BBC on:

Copyright 2026 BBC. All rights reserved. The BBC is not responsible for the content of external sites.Read about our approach to external linking.