UK water company allowed hackers to lurk undetected for nearly two years, regulator finds

2026-05-11T14:51:59Zbdb108e40e82fecb0c7261ad04ff4578b5d0af89d3ea35d4032778c37b4b849e
CCPACl0pCopy FailDirty FragICO fineKingdom Marketcybercrimedarknet marketdata breachdatabase deletioninsider misuselinux kernelprivacy settlementprivilege escalationransomwarevulnerabilityzero-day

What happened

Multiple security and privacy incidents: UK water company South Staffordshire Water was fined £963,900 by the ICO after the Cl0p ransomware group published personal data for 633,887 customers and employees (attack occurred Aug 2022). A new high-impact Linux kernel vulnerability dubbed “Dirty Frag” was disclosed — a second major bug in the same area as last month’s Copy Fail that reportedly allows low-privileged accounts to escalate to full administrative control. General Motors agreed to a record CCPA settlement of over $12 million over driver data handling. Slovak national Alan Bill was given

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
bdb108e40e82fecb0c7261ad04ff4578b5d0af89d3ea35d4032778c37b4b849e
Enrichment time
2026-05-11T14:51:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.