The Information Commissioner’s Office (ICO) has fined South Staffordshire Water and parent company, South Staffordshire Plc £963,900 following a cyber-attack that exposed the personal data of 633,887 individuals.
In 2020, an employee opened a phishing email containing a malicious attachment, enabling attackers to gain access to internal systems. This remained undetected for 20 months and hackers obtained domain administrator privileges, giving them extensive control.
The breach was eventually discovered in July 2022 after IT performance issues prompted an investigation. By then, more than 4.1 terabytes of personal data had been published on the dark web, including banking details, online account credentials, HR records and disability data.
The ICO concluded that the organisation failed to implement appropriate measures to protect personal data, as required under the UK GDPR. They breached:
- Article 5(1)(f) – Integrity and confidentiality: failure to keep personal data secure
- Article 32 – Security of processing: inadequate security measures and safeguards
The key weaknesses identified:
- Insufficient monitoring of IT systems
- Poor vulnerability management and unpatched systems
- Use of outdated software
- Weak access controls that enabled privilege escalation
These are fundamental cybersecurity practices – organisations should not rely on reactive indicators such as system failures/ransom demands to identify security incidents.
Organisations should adopt a proactive approach to cybersecurity and data protection:
- Strengthen core security controls – ensure systems are regularly patched and updated, retire unsupported software, implement comprehensive monitoring across IT environments.
- Carry out robust risk assessments – use Data Protection Impact Assessments to identify and assess high risk processing activities, maintain documentation of risks, controls, and decision-making processes.
- Invest in staff awareness – phishing remains one of the most common entry points for cyber-attacks. Regular training can help employees recognise, report, and respond.
- Improve data governance – apply least privilege access controls to limit access to data and regularly review retention policies to avoid holding unnecessary data.
- Prioritise early detection and incident response – regularly test detection capabilities and response procedures rather than relying on visible system disruption to uncover breaches.
This case demonstrates how one phishing email, combined with weaknesses in cybersecurity practices, can escalate into a large scale data breach. Cybersecurity is not only about prevention, but also detecting threats quickly, limiting impact and having safeguards in place to protect data.
If your organisation would like support with breach prevention training, breach management and reporting, get in touch with Hope & May today for tailored guidance and support.