South Staffordshire water (SSW), a company supplying 330 million litres of drinking water to 1.6 million people daily, has confirmed IT disruption due to a cyber attack.

SSW has confirmed that their safety and water distribution systems are still operational, so the disruption of their IT systems will not impact their ability to supply safe water to their customers, or their subsidiaries, Cambridge Water and South Staffs Water.

In their statement, they made it clear that:

This is thanks to the robust systems and control over water supply and quality we have in place at all times, as well as the quick work of our teams to respond to this incident and implement the additional measures we have put in place on a precautionary basis“.
We are experiencing disruption to our corporate IT network and our teams are working to resolve this as quickly as possible. It is important to stress that our customer service teams are operating as usual“.
We are working closely with the relevant government and regulatory authorities and will keep them, as well as our customers, updated as our investigations continue“.

Their full statement can be read here on their website.

SSW later reassured customers that all service teams are operating as usual suggesting that there is no risk of extended outages due to the cyberattack.

The attack

Just hours after the attack occurred, ransomware gang Cl0p claimed to have successfully hacked Thames Water via an announcement on their website hosted on the dark web.

Thames Water is the UK’s largest water supplier and wastewater treatment provider, serving Greater London and all areas surrounding the river Thames.

They have stated that they broke into and manipulated SCADA systems in order to cause harm to 15 million customers. They have also stated that they informed Thames Water of its network security inadequacies and claim that they acted responsibly by not encrypting their data and exfiltrating 5 TB from the compromised systems.

As it would not be safe to link to the original statement made by the ransomware gang we have chosen to extract key sections and display them below (the poor grammar is attributed to the statement originally being published in Russian):

“Thames Water supply much of critical water services to people and companies. This company is public and this means they bring water and sewage services to millions of people – Companies like this have much responsibility and we contact them and tell them that they have very bad holes in their systems. ALL SYSTEMS.”
“We spent months in the company systems and saw first-hand evidence of very bad practice. This company is all for money and does not deliver reliable service”.
“Cl0p is not a political organisation and we do not attack critical infrastructure or health organisations. We decide that we do not encrypt this company, but we show them that we have access to more than 5TB of data”.

Cl0p’s message that they do not attack critical infrastructure is somewhat disingenuous in a statement where they confirm they have attacked a company providing critical infrastructure.

Staffordshire or Thames?

It is unlikely that Thames Water has been impacted in any way by this group’s activities.

What is more likely is that the group have confused South Staffordshire Water with Thames Water, or that they are pretending that they have data from Thames Water in an attempt to extort two companies at the same time.

Thames Water is also a comparatively larger company, suggesting that the ransomware group were hoping they could leverage their attack on a smaller company to gain a larger ransom sum.

Cl0p has since released stolen data which they claim to have belonged to Thames water. This stolen data includes passports, screenshots from water treatment SCADA systemsdriver’s licences of employees, and more sensitive data.

However, none of the data can be attributed to Thames water. One key detail that suggests Cl0p is lying is a spreadsheet containing usernames, passwords, and email addresses, which belong to South Staffordshire employees:

 

Another one of the leaked documents is explicitly addressed to South Staffordshire PLC.

This information has led Thames Water to officially dispute all of the groups’ claims, in the statement shown below:

 

We are aware of reports in the media that Thames Water is facing a cyber-attack.
We want to reassure you that this is not the case, and we are sorry if the reports have caused distress.
As providers of an essential service, we take the security of our networks and systems very seriously and are focused on protecting them, so that we can continue to provide you with the services and support you need from us“.

The full statement can be read here.

Opportunism amongst Cyber Criminals

This recent attack shows the lack of morality held by cybercriminal groups.

Cl0p chose to target a water supplier in the middle of a major drought, with eight areas in the country currently imposing water ration policies and hosepipe bans.

Cybercriminals usually pick targets based on automated port-scanning software. Such software detects whether or not a network’s firewall has open ports, and so can be used to enter and spread malware. Cybercriminals also target organisations based on users who have fallen victim to phishing attacks. Such attacks rely on sending out thousands of emails, in the hope that users will be fooled into clicking a link or downloading a file.

Both methods of selecting organisations to infect with ransomware are indiscriminate towards the size, industry, or nationality.

This recent attack on South Staffordshire Water is likely to have originated with one of these methods of selection, and the hackers, if their statement is to be believed, waited several months before deciding to extort the water supplier. They also chose to extort the supplier during a major drought in order to place as much pressure as possible, with the aim of convincing them to pay the ransom.

Never Pay Ransoms

Cl0p’s recent act of releasing stolen data suggests that ransom negotiations have broken down between SSW and Cl0p.

Despite the leaked personal data, this is a positive outcome.

We advise that if an organisation is compromised by malware and asked by an extorter to pay a ransom for the return of their data, never pay the ransom. It is highly unlikely the organisation will receive all of their data back unencrypted, and they will become targets for future attacks.

Paying ransom also encourages cyber criminals to carry on performing attacks and provides them with capital to invest into producing more dangerous malware, and launching even larger ransomware campaigns.

TecSec Services Ltd is an IT Support and Risk Management provider. We have achieved Cyber Essentials, Cyber Essentials +, IASME Gold, and are an official IASME certification body. We have also achieved ISO 2701:2013, a substantial certification for our Information Security Management system.
Such certifications are one of the ways we help ensure incidents such as those experienced by South Staffordshire Water do not happen to us or our clients.
They show our stakeholders that our cyber security practices are impeccable and allow us to protect against all common cyber attacks.
We are currently offering two services that help identify if your organisation is at risk of being exploited by cybercriminals.
Our Free Cyber Security Training helps protect your staff against phishing attacks, by providing the best methods of identifying phishing emails:
Our Free Vulnerability Scan will help us understand if your organisation’s network has any external vulnerabilities that will give hackers the ability to spread malware: