20.9 C
New York
Wednesday, June 18, 2025

Southern Water says Black Basta ransomware assault value £4.5M in bills


United Kingdom water provider Southern Water has disclosed that it incurred prices of £4.5 million ($5.7M) resulting from a cyberattack it suffered in February 2024.

Southern Water is a non-public utility firm in southern England, offering water providers to 2.7 million prospects and wastewater providers to over 4.7 million prospects throughout Kent, Sussex, Hampshire, and the Isle of Wight.

The corporate provides 570 million liters of water by means of a 13,973 km community every day and manages 1,522 million liters of wastewater through a 40,058 km sewer system.

Roughly a yr again, Southern Water introduced that it suffered a safety breach, which did not impression its operations, monetary techniques, or customer-facing techniques.

The assault was claimed by the Black Basta ransomware gang, a infamous menace actor recognized for not hesitating to assault crucial infrastructure.

The corporate’s monetary report, first seen by DataBreaches.internet, determines the price of the Black Basta assault to be round £4,500,000 (web page 98). 

“In February 2024 we introduced that knowledge from a restricted a part of our server property had been stolen by means of an unlawful intrusion into our IT techniques,” reads the report.

“We engaged exterior cyber safety specialists and authorized advisers in response, in addition to contacting anybody whose private knowledge could have been in danger.”

“We now have incurred £4.5 million in responding to this distinctive incident through the yr.”

For perspective, the quantity is identical as Southern Water paid for air pollution administration operations final yr, not accounting for the reputational injury, authorized charges, and potential regulatory scrutiny which will accompany cybersecurity incidents.

Southern Water operating costs
Working prices diagram
Supply: Southern Water

Southern Water claims that it has contracted cybersecurity specialists to repeatedly monitor the darkish internet for knowledge leaks impacting them or their purchasers, which has not occurred but.

In the meantime, evaluation of the leaked inside chat logs from the Black Basta ransomware gang revealed that the water remedy firm allegedly proposed to pay the ransomware actors £750,000 ($950k) on February 12, 2024.

Though the attackers initially demanded a cost of $3,500,000, by the tip of February 2024, the corporate’s entry was faraway from Black Basta’s extortion website, indicating that the 2 may need reached some settlement.

When requested by The Register if the corporate paid the ransomware gang, a spokesperson repeated previous statements that didn’t make clear something.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles