13/05/2026
A £1 million fine linked to outdated systems and poor cybersecurity controls.
South Staffordshire Water has been fined after a cyber attack exposed the personal data of more than 633,000 people.
The breach reportedly started from a phishing email, allowing attackers to install malware, which stayed undetected for almost two years before moving through the network and gaining administrator access.
Investigators found issues including unsupported systems, unpatched vulnerabilities, poor monitoring, and weak internal controls.
The breach reportedly began with a phishing email, allowing attackers to install malware that remained undetected for almost two years before moving through the network and gaining administrator access.
South Staffordshire Water fined £963K after hackers lurked undetected for 20 months on Windows Server 2003, leaked 633,000 records