Poor security left hackers inside water company network for nearly two years
The UK’s data protection regulator, the Information Commissioner’s Office (ICO), fined South Staffordshire Water’s parent company £963,900 over security failures linked to a cyberattack that exposed the personal data of 633,887 people. According to the ICO, the South Staffordshire breach began in September 2020 with a phishing email that tricked an employee into opening an attachment, allowing attackers to install…
Hackers remained undetected for nearly two years
📈
2 years
Dwell time
Fine issued to South Staffordshire Water
⚡
£963,900
ICO fine
Personal data of customers compromised
⭐
633,887
Customers exposed