Posts

Showing posts from 2026

UK Cybercrime Journal: Inside the Cl0p attack on South Staffs Water

Image
  What Happened: On 11 May 2026, the UK Information Commissioner’s Office (ICO) fined South Staffordshire Water £963,900 after the Cl0p ransomware group lurked completely undetected in its network for nearly two years. Initial access reportedly occurred via a malicious phishing email in September 2020, which downloaded Cl0p’s Get2Loader malware and their SDBBOT backdoor to establish persistence.  The breach itself, however, was only discovered two years later in July 2022 when staff began investigating IT performance slowdowns. South Staffs Water ultimately found out that 4.1 terabytes of data was exfiltrated and the personal data of 633,887 customers and employees being published in August 2022 on Cl0p’s Tor data leak site. The ICO’s investigation also revealed a staggering list of systemic failures.  The ICO exposed that South Staff’s outsourced Security Operations Center (SOC) was blind to 95% of the network and that they conducted zero internal or external vulnerabili...