ctipilot.ch

South Staffordshire Water ICO fine

incident · incident:south-staffordshire-water-ico-2026

ICO fines South Staffordshire Water £963,900 — Cl0p ZeroLogon intrusion, 20-month dwell, 5% SOC coverage; a UK NIS2/CER precedent.

Coverage timeline
2
first 2026-05-11 → last 2026-05-12
Peak priority
high
1 high · 1 notable
Sources cited
4
4 hosts
Sections touched
2
active-threats, weekly-incidents-recap
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.1 · see below
2026-05-112 appearances2026-05-12

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-05-12/ico-fines-south-staffordshire-water-963-900-water-sector-oes · ATT&CK page ↗

Story timeline

  1. 2026-05-12ICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record
    active-threatsICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The
  2. 2026-05-11South Staffordshire Water — ICO £963,900 fine
    weekly-incidents-recap

Where this entity is cited

  • weekly-incidents-recap1
  • active-threats1

Source distribution

  • attack.mitre.org1 (25%)
  • ico.org.uk1 (25%)
  • therecord.media1 (25%)
  • theregister.com1 (25%)

explore in graph

Entries about South Staffordshire Water ICO fine (2)

2026-05-12 · view entry permalink →

HIGH

ICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record

The UK Information Commissioner's Office on 2026-05-11 issued a £963,900 fine against South Staffordshire Plc and its water-supply subsidiary for the 2020–2022 intrusion. The ICO's published findings cite inadequate vulnerability management, unpatched critical systems, obsolete unsupported software (the estate still contained Windows Server 2003, EOL since July 2015), and incomplete SIEM coverage; the regulator does not name a CVE or threat actor in its public notice. The technical kill-chain detail — phishing initial access in September 2020 → CVE-2020-1472 (ZeroLogon, T1068) against two unpatched domain controllers → domain admin → ~20 months of unimpeded lateral movement → detection in July 2022 when IT performance degraded — comes from The Record's reporting, as does the Cl0p attribution. The ICO press release records that data on about 1.85 million customers (approximately 750,000 current and 1.1 million former) was held by the company, of which 633,887 individuals had data published on the dark web, and that the published dataset totalled over 4.1 TB including customer credentials, bank account/sort codes, Priority Services Register data (from which disability status can be inferred) and HR records (The Register, 2026-05-11). The fine was reduced 40% on the basis of early admission and cooperative engagement; South Staffordshire agreed not to appeal.

Why it matters to us: The ICO action is the first significant post-Cyber-Security-and-Resilience-Bill UK regulatory action against a water-sector OES, and the regulator's operational findings transfer verbatim to NIS2 Article 21 technical measures and the German KRITIS-DachG public-administration scope that came into force this spring. Concrete defender takeaway: (a) measure your actual SIEM/XDR coverage percentage by hostname inventory rather than by sensor-licence count — partial coverage on a high-value subset is materially worse than uniform sampling; (b) the ZeroLogon pivot reported by The Record is a long-tail patch-management hygiene point on domain controllers any SOC can audit against; (c) detection logic that survives this case maps to Sysmon-class auditing of DC authentication events — 4742 (account changes) and 4769 Kerberos service-ticket anomalies — after vendor disclosure of any DC-impacting CVE.

incident12 May 05:00Zmulti-sourceOpen finding ↗

2026-05-11 · view entry permalink →

NOTABLE

South Staffordshire Water — ICO £963,900 fine

ICO fines South Staffordshire Water £963,900 over the 2022 Cl0p ZeroLogon kill-chain intrusion (daily 2026-05-12). The water-sector OES finding with the partial SIEM coverage detail (5% host-inventory coverage) is the operational lesson for any utility / critical-infrastructure operator with patchy telemetry. Regulatory significance: the ICO penalty on a critical-infrastructure operator gives Swiss BACS / EU NIS2 competent authorities a template fine-calculation for analogous deficiencies (daily 2026-05-12).

incident11 May 05:00Zmulti-sourceOpen finding ↗