ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Southern Water faces scrutiny over alleged ransom payment to hackers

Southern Water has declined to confirm or deny allegations that it offered a $750,000 ransom payment to the ransomware group Black Basta following a cyberattack in early 2024. The claim surfaced after a leak of internal communications among Black Basta members, shedding light on the negotiations between the cyber criminals and the water utility company.


The attack, which reportedly occurred in February 2024, saw Southern Water’s IT systems compromised. While the company maintains that its operations and services to customers remained unaffected, a significant amount of data was allegedly exfiltrated and subsequently leaked on the dark web. Black Basta, a notorious ransomware gang known for targeting high-profile organizations, initially demanded a ransom payment of $3.5 million. However, leaked chat logs suggest that Southern Water countered with a significantly lower offer of $750,000.


According to these chat logs, Southern Water appeared unwilling to meet the attackers’ original demand. A message attributed to the company’s representative states, “Hello. I discussed your offer with the Board, and as I expected, your current demand is still too steep for us to even consider.” The representative goes on to acknowledge the challenges posed by the breach but expresses a willingness to negotiate, saying, “We’re now offering to pay you $750,000 in exchange for a speedy resolution of this incident.”


It remains unclear whether Black Basta accepted the offer. While a message from a Black Basta member named “Tinker” on March 19, 2024, suggests that Southern Water had already paid—stating, “These have already paid, remember?”—there is no definitive confirmation within the leaked communications that the transaction took place. Additionally, a log entry from Black Basta’s leader, known as “GG,” simply lists “southernwater.co.uk – removal log,” further complicating the matter.


In response to inquiries about the ransom payment, a spokesperson for Southern Water neither confirmed nor denied the claims. The spokesperson stated, “As soon as we became aware, over a year ago, of an illegal intrusion affecting our IT systems (not affecting our operations or services to customers), we informed all relevant bodies, including NCSC and Defra. We and our advisers worked closely with NCSC throughout the incident.”


The cybersecurity firm HudsonRock facilitated the investigation into Southern Water’s potential ransom payment, using its BlackBastaGPT tool to analyze leaked chat data. However, The Register, which conducted an independent review of the logs, noted that the AI-powered tool often produced inaccurate results, including misattributing conversations and generating misleading excerpts. As such, any conclusions drawn from the tool’s findings should be treated with caution.


Southern Water, which provides water and wastewater services to customers in Kent, Sussex, Hampshire, and the Isle of Wight, has not disclosed specific details about the extent of the data breach. Reports indicate that approximately 750 GB of data was exfiltrated during the attack. The company has continued to work with the UK’s National Cyber Security Centre (NCSC) and the Department for Environment, Food & Rural Affairs (Defra) to mitigate any potential fallout from the incident.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543