Southern Water [1] [2] [3] [4] [5] [6], a water company serving 2.5 million customers and providing wastewater services to over 4.7 million customers in Kent [2], Sussex [2], Hampshire [2], and the Isle of Wight [2], recently experienced a cyber attack resulting in a data breach. This breach potentially compromised personal and financial information of 5-10% of its customers, including contact details and national security numbers [1].

Description

Southern Water is actively working with technical advisors to identify the customers whose data may be at risk. They have also engaged independent cyber security experts to monitor the dark web for any signs of the stolen data being published [5]. The company has promptly notified the Information Commissioner’s Office and is closely collaborating with the National Cyber Security Centre. As a precautionary measure, affected customers have been offered fraud monitoring services [6]. Southern Water is providing support and guidance to those affected, including advice on potential risks such as phishing attacks and identity theft [3].

Notifications will be sent to an estimated 230,000 to 460,000 individuals, which accounts for 5-10% of Southern Water’s customer base. Additionally, all current employees and some former employees will also be notified [3]. The company is committed to ensuring that its operations and services to customers remain unaffected by the breach. They are actively monitoring for any suspicious activity and will provide updates on the situation through their website and social media channels.

Conclusion

The cyber attack and data breach experienced by Southern Water have significant implications for the affected customers and the company itself. Southern Water is taking immediate action to mitigate the risks and support those impacted. The incident highlights the ongoing challenges faced by the water industry, with utilities already burdened by debt as they upgrade their infrastructure. In 2021, Macquarie [6], the owner of Southern Water [6], injected £550 million in funding to support the company. This incident serves as a reminder of the importance of robust cyber security measures and the need for continuous vigilance in protecting sensitive customer information.

References

[1] https://www.cybersecurity-review.com/uk-contact-details-and-national-security-numbers-could-have-been-stolen-from-southern-water-customers-following-cyber-attack/
[2] https://www.bbc.com/news/uk-england-kent-68284475.amp
[3] https://www.infosecurity-magazine.com/news/southern-water-notifies-customers/
[4] https://www.southernwater.co.uk/the-news-room/the-media-centre/2024/february/cyber-attack-update-for-customers
[5] https://www.kentonline.co.uk/kent/news/amp/water-company-with-thousands-of-kent-customers-confirms-cybe-301741/
[6] https://finance.yahoo.com/news/southern-water-warns-500-000-201555648.html?fr=sycsrp_catchall