Ransomware

Major US, UK Water Companies Hit by Ransomware

Two major water companies, Veolia in the US and Southern Water in the UK, have been targeted in ransomware attacks that resulted in data breaches.

ICS malware Fuxnet

Two major water companies, Veolia North America in the United States and Southern Water in the United Kingdom, have been targeted in ransomware attacks that resulted in data breaches.

Veolia describes itself as the world’s largest private player in the water sector, providing water and wastewater services to tens of millions of people. 

In a notice posted on its website, Veolia North America revealed that its Municipal Water division was hit by ransomware last week. In response to the incident, the company took down the targeted backend systems and servers, which disrupted online bill payment systems.

“This incident seems to have been confined to our internal back-end systems at Veolia North America, and there is no evidence to suggest it affected our water or wastewater treatment operations,” Veolia said.

The water company has also determined that the personal information of “a limited number of individuals” may have been compromised. Affected people will be notified by the firm.

No known ransomware group appears to have taken credit for the attack on Veolia.

Across the pond, a ransomware group targeted Southern Water, which provides water services to 2.5 million customers and wastewater services to 4.7 million customers in the South of England.

A statement issued by the company on Tuesday confirmed that suspicious activity was detected on its systems and an investigation has been launched. 

Advertisement. Scroll to continue reading.

The statement came after the Black Basta ransomware group listed Southern Water on its leak website, claiming to have stolen 750 Gb of files, including ones containing personal information and corporate documents. The hackers posted several screenshots showing that they obtained identification document scans (passports and driver’s licenses) and other documents containing personal information. 

The cybercriminals are threatening to make the stolen data public in five days if Southern Water refuses to pay a ransom.

The water utility is investigating the claims, but has currently found no evidence that customer relationship or financial systems have been impacted. “Our services are not impacted and are operating normally,” it said.

The water sector in the West has been increasingly targeted by malicious cyber actors. Hackers believed to be affiliated with the Iranian government last year targeted industrial control systems (ICS) at multiple water facilities in the United States.

In Ireland, a cyberattack targeting the systems of a small utility caused significant disruption, leaving people without water for two days.   

Related: US Gov Publishes Cybersecurity Guidance for Water and Wastewater Utilities

Related: States and Congress Wrestle With Cybersecurity After Iran Attacks Small Town Water Utilities

Related: CISA Offering Free Vulnerability Scanning Service to Water Utilities

Related Content

Ransomware

Organizations need to look beyond preventive measures when it comes to dealing with today’s ransomware threats and invest in ransomware response.

Ransomware

Philadelphia-based real estate company Brandywine Realty Trust shuts down systems following a ransomware attack.

Data Breaches

University System of Georgia says Social Security numbers and bank account numbers were compromised in the May 2023 MOVEit hack.

Ransomware

Charges and sanctions announced against Dimitry Yuryevich Khoroshev, the alleged developer and operator of LockBit ransomware.

Ransomware

The City of Wichita, Kansas, has shut down its network after falling victim to a file-encrypting ransomware attack.

Cybercrime

Yaroslav Vasinskyi was sentenced to 13 years and seven months in prison for his alleged role in the REvil ransomware operation.

Data Breaches

Dropbox says hackers breached its Sign production environment and accessed customer email addresses and hashed passwords. 

Data Breaches

Financial Business and Consumer Solutions (FBCS) says compromised information may include names, dates of birth, Social Security numbers, and account information.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version