The UK Information Commissioner’s Office fined South Staffordshire Water £963,900 after a ransomware-linked breach tied to the Cl0p group exposed personal data from 633,887 customers and employees. Investigators said the intrusion began in September 2020 with a phishing email that deployed Get2Loader and the SDBBOT backdoor, allowing attackers to remain inside the utility’s network until July 2022, when staff began investigating IT performance problems. South Staffordshire Water later found that 4.1 TB of data had been exfiltrated and that the stolen information was published on Cl0p’s Tor leak site in August 2022.
The ICO said the breach was enabled by major security failures across the organization’s environment, including an outsourced SOC with visibility into only 5% of the network, no internal or external vulnerability scanning for 18 months, legacy Windows Server 2003 systems, and unpatched domain controllers exposed to ZeroLogon (CVE-2020-1472). The case underscores how weak monitoring, patching, and vulnerability management left a UK critical national infrastructure provider vulnerable to a prolonged compromise without requiring especially sophisticated attacker tradecraft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-11, the UK Information Commissioner's Office fined South Staffordshire Water £963,900 for the ransomware-related data breach. The ICO cited major security failings including poor network visibility, lack of vulnerability scanning, legacy systems, and unpatched ZeroLogon-vulnerable domain controllers.
On 2026-04-23, South Staffordshire Plc and South Staffordshire Water Plc entered into a voluntary settlement with the UK ICO, admitting UK GDPR infringements tied to the Cl0p-related breach. The companies accepted a 40% discount on the monetary penalty and agreed not to appeal the notice.
On 2022-08-18, reports initially linking a ransomware incident to Thames Water were corrected after Thames Water denied being affected and Cl0p updated its leak site to name South Staffordshire Plc instead. South Staffordshire said the attack impacted only its corporate IT network and did not disrupt water supply or operational systems.
In August 2022, personal data belonging to 633,887 customers and employees was published on Cl0p's Tor leak site. South Staffordshire Water later determined that 4.1 terabytes of data had been exfiltrated.
In July 2022, South Staffordshire Water uncovered the intrusion while investigating IT performance problems. The attackers had remained undetected in the environment for nearly two years.
In September 2020, attackers gained initial access to South Staffordshire Water through a phishing email. The intrusion deployed Get2Loader and the SDBBOT backdoor, beginning a long-running compromise later tied to the Cl0p group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcebleepingcomputer.com
Open sourcetheregister.com
Open sourceblog.bushidotoken.net
Open sourcetheregister.com
Open sourcebleepingcomputer.com
Open sourceico.org.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.