UK’s Southern Water reports huge leak - hundreds of thousands of customer’s data stolen by hackers

Data leak
(Image credit: Shutterstock)

Up to 470,000 UK customers of water provider Southern Water may have had their data stolen by hackers, the company has warned.

While investigations into exactly how many customers have been affected are still ongoing, Southern Water released a statement saying that they are planning to notify “5 to 10 percent” of its customers.

A BBC report said included in the stolen data were customers’ bank account details and reference numbers, national insurance numbers and dates of birth. Southern Water has not commented on exactly what data has been stolen.

Another data leak? Dam it!

A statement from Southern Water spokesperson Simon Fluendy confirmed to TechCrunch that between 235,000 to 470,000 of its 4.7 million customers' data had been stolen in the breach.

The company also plans to notify its 6,000 current employees and a number of former employees whose data may have also been stolen by the hackers.

While Southern Water has not commented on how their networks were breached, shortly after the incident a cyber-gang known as Black Basta posted that they had stolen 750 gigabytes of data from the company, and would release it if a ransom was not paid.

The gang also posted images supposedly confirming their possession of the data which included sensitive information such as employee passports.

Southern Water has said that it is working with experts to determine the extent of the damage and has notified the Information Commissioner's Office (ICO) about the incident. The ICO and the National Cyber Security Centre recently released a joint letter urging members of the public to not pay ransoms if their data is stolen.

More from TechRadar Pro

Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division),  then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.