ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

South Staffs Water says customer data has been leaked by hackers on the Dark Web

South Staffordshire PLC, the parent company of South Staffordshire Water and Cambridge Water, has confirmed that the data breach it suffered in August compromised the personal and financial information of its customers.Earlier this year, South Staffordshire PLC suffered a major ransomware attack that disrupted its corporate IT network but, fortunately, did not affect the usual supply of water to the company’s customers or to those of its subsidiaries - Cambridge Water and South Staffs Water.“This is thanks to the robust systems and controls over water supply and quality we have in place at all times, as well as the quick work of our teams to respond to this incident and implement the additional measures we have put in place on a precautionary basis,” the company said.The company brought in third-party IT forensic experts to investigate the cyber attack and informed various authorities, such as the National Crime Agency, the National Cyber Security Centre, the Information Commissioners Office (ICO), OFWAT, the Consumer Council for Water, and the Drinking water Commissioner about the incident.In a notification sent to affected customers, the company has now confirmed that the cyber attack compromised financial information like bank sort codes and account numbers of certain customers who paid their water bills via Direct Debit. Sensitive personal information like names and addresses and other personal information of customers were also compromised and have been published by hackers on the Dark Web.South Staffs Water managing director, Andy Willicott, said, “Consumers can have complete confidence that the water we supply is safe.“We understand that customers trust us to keep their data safe and I’d personally like to say sorry to all those customers impacted – we’ll be doing what we can to support you through this. We will continue to invest in protecting our customers, our systems, and our data,” Willicott added.Commenting on hackers publishing the stolen data on the Dark Web, Javvad Malik, lead security awareness advocate at KnowBe4, said, “The breach highlights how organisations need to be mindful of all types of data they have and ensure it is all protected. While protecting critical systems is important, equally so is customer information.“While credit or debit cards can easily be canceled and re-issued, other personal information such as names, date of birth, address, etc is not so easy to change - and if exposed, can be used by criminals to steal identities, or use the information to scam the victims via phishing attacks.“Ultimately, all data has value - even if data is of low importance, it can be combined with other forms of data to be quite problematic for individuals,” he added.

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543