UK water giant admits attackers broke into system as gang holds it to ransom
- Reference: 1706010530
- News link: https://www.theregister.co.uk/2024/01/23/southern_water_confirms_cyberattack/
- Source link:
The Black Basta ransomware group claimed the attack while publishing a snippet of the data it allegedly stole, which included:
Scans of identity documents such as passports and driving licenses
Documents that appear to be HR-related, displaying the personal data of what could be customers, including home address, office address, dates of birth, nationalities, and email addresses
Corporate car-leasing documents exposing personal data
Southern Water provides water services to 2.5 million customers and wastewater services to 4.7 million customers in the southern regions of the England. The company said in a statement that if it finds evidence of customer or employee data being stolen, it will notify the affected individuals.
Inputting some of the details leaked on the cybercriminals' blog into a search engine suggests the details of both Southern Water employees and customers may be compromised.
"We are aware of a claim by cyber criminals that data has been stolen from some of our IT systems," the organization said.
[1]
"We had previously detected suspicious activity, and had launched an investigation, led by independent cyber security specialists.
[2]
[3]
"Since then, a limited amount of data has been published. However, at this point, there is no evidence that our customer relationships or financial systems have been affected. Our services are not impacted and are operating normally."
The UK government, regulators, and the Information Commissioner's Office (ICO) have been informed, it went on to say.
[4]
It's unclear where the root cause of the breach lies. Some documents leaked online are branded with Greensands logos – the parent company of Southern Water.
Black Basta said it stole 750 GB worth of data in total, comprised of personal data and corporate documents, which is consistent with the small sample leaked online.
[5]Australia imposes cyber sanctions on Russian it says ransomwared health insurer
[6]Slug slimes aerospace biz AerCap with ransomware, brags about 1TB theft
[7]Subway's data torpedoed by LockBit, ransomware gang claims
[8]Thieves steal 35.5M customers' data from Vans sneakers maker
The gang said a full exposure of data will take place in six days if a ransom isn't paid.
The water and wastewater industry has become an increasingly popular target for cybercriminals over the past year, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to prioritize engagement with it to the same degree as the healthcare and education sectors.
"To support and reinforce EPA's ongoing efforts, CISA is prioritizing the water sector in its engagements and efforts due to the significant level of cyber and physical risk associated with this sector combined with its relative lack of resources to address those risks," reads the agency's dedicated page for the water industry.
[9]
Iranian attackers are thought to be behind an [10]attack on a Pennsylvania water authority in November 2023 after compromising Unitronics programmable logic controllers.
Attacks on Western critical infrastructure have been an acute concern for cybersecurity authorities in recent years, and the UK National Cyber Security Centre (NCSC) has recently issued an [11]advisory highlighting the threat to critical infrastructure, including water organizations.
In 2022, now-dismantled ransomware crew Clop [12]claimed an attack on Thames Water but the silly skids instead breached South Staffordshire – parent company to South Staffs Water and Cambridge Water. ®
Get our [13]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Za-wu7KKzWZPVXzUFf8DigAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Za-wu7KKzWZPVXzUFf8DigAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Za-wu7KKzWZPVXzUFf8DigAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Za-wu7KKzWZPVXzUFf8DigAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2024/01/23/australia_medibank_private_attacker_named/
[6] https://www.theregister.com/2024/01/22/ransomware_aercap_loandepot/
[7] https://www.theregister.com/2024/01/22/subways_data_toasted_by_lockbit/
[8] https://www.theregister.com/2024/01/19/vf_corp_ransomware_impact/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Za-wu7KKzWZPVXzUFf8DigAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2023/11/29/water_authority_ciso_iran/
[11] https://www.ncsc.gov.uk/news/ncsc-warns-enduring-significant-threat-to-uks-critical-infrastructure
[12] https://www.theregister.com/2022/08/18/clop_ransomware_uk_water/
[13] https://whitepapers.theregister.com/
Not the first time my data has been breached by Southern Water
I’ve had to phone up Southern Water before, to discuss a broken drain leading out from my property. They couldn’t help.
Later that day, a local plumber pulled up and asked if I needed any work doing. I asked how he knew and he said “I’ve got a mate who works at Southern Water.”
Re: Not the first time my data has been breached by Southern Water
You could always report the breach to ICO so they could tell you to switch your water supplier and bugger off...
For your safety and security
We will indefinitely retain "Scans of identity documents such as passports and driving licenses". You can be assured our (your) data is as leaky as our pipes.
"as leaky as our pipes"
Is that possible?
Iranian attackers are thought to be behind an attack on a Pennsylvania water authority.
I'm waiting for Yemini hacker accusations. I give it a month tops before America unearths a previously unknown hackorz network.
Not saying there aren't Iranian/Russian/Chinese or North Korean hackers but I am saying it's odd it's nearly always those countries.
Southern Water
In a previous incarnation SW were one of our customers. The kindest comment I can make about their manglement is "not impressed". The grunts who actually did the work definitely classed as long suffering.
> ... making off with a "limited amount of data."
Would that limit be "the total amount of data that Southern Water have"?
Wait a minute...
Why the hell do Southern Water (or indeed any utility company) need to collect any personally identification? You are buying services from them; the only thing they need to know is (a) an address and (b) that the money keeps coming in. Some sort of customer number to link payments to location might be handy, but that is all they *need* until such time as you wish to terminate their service. At that point, it's reasonable that they require some sort of evidence that *you* are a person who has a right to terminate it (wouldn't want any Tom, Dick, or Harry turning my water off!) but it's *not* reasonable that they keep any such identifiable documentation... yes, send us a scan of your rates bill with your name and address, and we will note on our database that this was the document used to identify you.
What possible reason can there be to gather this sort of identification other than for this final case?
" The UK government, regulators, and the Information Commissioner's Office (ICO) have been informed, it went on to say. "
I bet Southern Water can't wait for the wonderful merriment of them doing the square root of fuck all about it.