UK Water Company Fined After Customers' Information Posted Online
South Staffordshire Water faces nearly £1 million in fines after a cyber attack exposed customer data that ended up on the dark web for almost two years.
Source
DataBreaches.net
Original headline: UK: Regulator fines water company almost £1m for cybersecurity failures
Plain-English summary by GetCyberRight. Read the full report at the source above.
The UK's Information Commissioner's Office has fined South Staffordshire Water £963,900 after the utility company suffered a cyber attack. The attack started in September 2020 and continued until July
- During that time, hackers extracted personal information belonging to the company's customers and published it on the dark web, where criminals buy and sell stolen data. If you are a customer of South Staffordshire Water and had an account between September 2020 and July 2022, your personal information may have been stolen and posted online. The fine was issued on May 7, indicating that the company did not have adequate security measures in place to protect customer data. When information sits on the dark web for nearly two years, criminals have plenty of time to use it for identity theft, scams, or fraud. Here is what South Staffordshire Water customers should do:
- Contact South Staffordshire Water directly to find out exactly what information was exposed and what protection services they are offering to affected customers.
- Change your password for your water company account and any other accounts where you used the same password.
- Watch your bank and credit card statements carefully for unfamiliar charges.
- Be extremely cautious of emails, text messages, or phone calls that mention your water service or bills. Scammers often use stolen data to make their messages look legitimate.
- Sign up for free credit monitoring if the water company offers it, or use a service like Credit Karma to watch for new accounts opened in your name. This incident shows that utility companies, which have our information because we need their services, can be weak links in data protection. You cannot choose whether to give them your data if you want water or electricity. That is why these companies face large fines when they fail to protect it. Going forward, use unique passwords for every account, especially for services connected to your home address and payment information. Enable two-factor authentication wherever possible. These steps limit the damage when one company fails to protect your data properly.
Curated from trusted cybersecurity sources by GetCyberRight
Source: DataBreaches.netStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
The Supply Chain Attack That Could Affect Your Small Business
A popular software component used by developers was compromised with credential-stealing malware, putting small businesses at risk without their knowledge.
4 min readSupply Chain Attacks Hit Small Businesses Too: What Families Need to Know
A popular software package used by developers building small business sites was compromised with credential-stealing malware, affecting millions of downloads.
3 min read
Memorial Day Sales Are Not a Cybersecurity Issue
This is a shopping deals article, not a security concern. No action needed from families regarding online safety.
1 min readMicrosoft Edge Just Fixed a Password Security Flaw You Didn't Know Existed
Edge browsers loaded all saved passwords into memory at startup, exposing them to malware. Microsoft's new update fixes this, but it reveals bigger risks with browser password storage.
4 min read