Overview
- The UK data watchdog issued the penalty Monday after the company’s early admission led to a 40% reduction from the initial sum.
- The breach began with a phishing email in September 2020 that installed malware and went undetected for about 20 months.
- The attacker gained domain administrator rights and used Remote Desktop Protocol to reach 20 endpoints between May and August 2022.
- The leak exposed data on 633,887 people, with more than 4.1 TB of names, contact details, bank and login data, and National Insurance numbers published on the dark web.
- Investigators found weak access controls, monitoring that covered about 5% of systems, unsupported software such as Windows Server 2003, and poor patching, which the regulator says other water firms must now address.