Black Basta claims ransomware attack on UK utility Southern Water
- Organization
- Southern Water
- Exploit
- Ransomware
- Industry
- Water Utilities
The Black Basta ransomware group named Southern Water on its Tor leak site on January 22, 2024, claiming to hold about 750 gigabytes of data taken from the English water and wastewater company. The group published sample material said to include scans of passports and identity cards along with corporate documents, and set a deadline of February 29, 2024 to release the remainder.
Southern Water supplies drinking water and wastewater services across Hampshire, the Isle of Wight, West Sussex, East Sussex and Kent, serving roughly 4.6 million customers and employing more than 6,000 people. The company said it had detected suspicious activity on its systems and had brought in independent cybersecurity specialists to investigate.
In a statement issued the day after the listing appeared, Southern Water acknowledged that a limited amount of data had been published and said usual services had not been affected. It reported no evidence that customer relationships or financial systems had been touched, and said water and wastewater treatment operations continued as normal.
The utility notified the UK government, the Information Commissioner's Office and other regulators, and said it was following National Cyber Security Centre guidance. It did not confirm how much data the attackers held. The 750GB figure and the description of its contents came from Black Basta, not from the company.