📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

South Staffs Water - Customers Criminal Cyber-Attack.

Options
Hi, I have today received notification from South Staffs Water that due to a cyber attack back in August that my banking details and personal details are now accessibly via the dark web to criminals. The letter is 6 pages long. One piece of advice is for me to pay £25 to set up Protective Registration with CIFAS. This informs lenders that you think your data could be at risk of fraud, due to this cyber attack. Should I, as the customer, be able to get this paid for by South Staffs? It is no faulty of mine after all? Any feedback be welcome.
«13

Comments

  • Swipe
    Swipe Posts: 5,648 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    I would push for them to pay for it. If you get no joy, take it up with your MP.
  • DullGreyGuy
    DullGreyGuy Posts: 18,613 Forumite
    10,000 Posts Second Anniversary Name Dropper
    Are they offering compensation of £25 or more? In which case its not too unreasonable to say that the compensation should be used to fund the CIFAS registration if you decide to use it. 
  • Evening All,

    I am after some advice about this, please. I received the letter today and just read through it. No apology for the breach, just almost blaming us, the customer and what steps WE can take to avoid fraudulent activity!!!! The letter says that the "impacted data" included names and address of customers - alongside sort codes and account numbers.

    On their company website, the managing director 'apologised' for the incident, although the letter expressed "regret" and did not actually say sorry. It then goes on to say "Consumers can have complete confidence that the water we supply is safe." !!!!! WHAT!!!!! It's not the water that has been hacked, it's our personal financial details.

    The letter is very frustrating. The managing director keeps trying to minimise the issue and even takes the opportunity to remind customers to 'always be vigilant of fraud and wary of anyone who asks you for personal information.' !!!!!!!!!!!!!!!!!!!!!!!!

    The letter said: "The investigation found data related to some of our current customers who pay for their water bill via direct debit was accessed by the group responsible for the attack and was subsequently published on the part of the internet not accessible via search engines - known as the dark web."

    I mean, where do I stand legally? Is there anything that can be done, or have they covered themselves from a GDPR point of view in terms of following the steps necessary, whatever they are?

    Kind Regards,

    Patrick.



  • billy2shots
    billy2shots Posts: 1,125 Forumite
    Sixth Anniversary 1,000 Posts Name Dropper
    Evening All,

    I am after some advice about this, please. I received the letter today and just read through it. No apology for the breach, just almost blaming us, the customer and what steps WE can take to avoid fraudulent activity!!!! The letter says that the "impacted data" included names and address of customers - alongside sort codes and account numbers.

    On their company website, the managing director 'apologised' for the incident, although the letter expressed "regret" and did not actually say sorry. It then goes on to say "Consumers can have complete confidence that the water we supply is safe." !!!!! WHAT!!!!! It's not the water that has been hacked, it's our personal financial details.

    The letter is very frustrating. The managing director keeps trying to minimise the issue and even takes the opportunity to remind customers to 'always be vigilant of fraud and wary of anyone who asks you for personal information.' !!!!!!!!!!!!!!!!!!!!!!!!

    The letter said: "The investigation found data related to some of our current customers who pay for their water bill via direct debit was accessed by the group responsible for the attack and was subsequently published on the part of the internet not accessible via search engines - known as the dark web."

    I mean, where do I stand legally? Is there anything that can be done, or have they covered themselves from a GDPR point of view in terms of following the steps necessary, whatever they are?

    Kind Regards,

    Patrick.



    How much do you want?
  • MattMattMattUK
    MattMattMattUK Posts: 11,294 Forumite
    10,000 Posts Fourth Anniversary Name Dropper
    I mean, where do I stand legally? Is there anything that can be done, or have they covered themselves from a GDPR point of view in terms of following the steps necessary, whatever they are?
    The ICO will oversee their response to the data breach. They have reported to the ICO, they will be fined, they will have to change/upgrade their systems, they may be required to provide CIFAS protective registration to people who were part of the data breach. 

    What you do is keep an eye on your credit files as everyone should do and carry on as normal. 
  • FreedomBringsPeace
    FreedomBringsPeace Posts: 98 Forumite
    10 Posts First Anniversary Name Dropper
    edited 13 January 2023 at 1:31PM
    Apparently tberes been a serious data breach at south staffordshire water. Alot of staff and customers data is now visible on the dark web, im quite concerned about this. What do i do if anything? 
  • You don't need to do anything.
  • CKhalvashi
    CKhalvashi Posts: 12,134 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    If you are personally affected it will be recommended to change any passwords, including those that use the same login details as those for your water account.

    In future I'd recommend using a throwaway email account that forwards to your main one to ensure you are free from spam, I've done this for years.

    Other than this at this stage there isn't a lot that can be done.
    💙💛 💔
  • p00hsticks
    p00hsticks Posts: 14,461 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    Have you actually received a letter from South Staffs Water ?
    I understand from this article that they've written to al lthose customers potentially affected advising them what steps to take.
    (From this report it, It sounds like a bit of a botch job on the part of the hackers - they actually hacked South Staffs but made their ransom demand to Thames water, and were then bemused when Thames didn't respond to them!)  

  • I had the letter this morning (Cambridge Water customer). Not worried about passwords as I don’t have have one with them. 
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.2K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.7K Spending & Discounts
  • 244.2K Work, Benefits & Business
  • 599.3K Mortgages, Homes & Bills
  • 177K Life & Family
  • 257.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.