A phishing email landed in a UK water company’s inbox in September 2020. The attackers stayed for 20 months. By the time they were detected, the Cl0p ransomware group had walked off with personal data on 633,887 customers and employees, and the Information Commissioner’s Office was preparing a £963,900 fine. This isn’t a cybersecurity story about a fancy zero-day or a nation-state APT campaign. It’s about something more common and more uncomfortable: nobody noticed for almost two years.
South Staffordshire Water is now the cautionary tale that should be on every detection engineer’s whiteboard. The intrusion timeline puts hard numbers on a problem most security teams handwave: dwell time is still measured in months, sometimes years, and the controls meant to catch slow attackers are mostly tuned to catch fast ones.
The Phishing Email That Lived 20 Months in Production
The attack chain reads like a standard exam question. Phishing email lands. Employee opens attachment. Malware installs. Attackers establish persistence and start moving laterally. None of this is novel. What’s striking is the duration. From September 2020 to August 2022, the intruders had time to map the network, collect credentials, locate sensitive data stores, and stage exfiltration. They had time to do all of that twice if they wanted to.
Twenty months is roughly six times the global median dwell time reported by major incident response firms last year. It is also longer than most SIEM platforms retain hot log data by default. If you only keep 90 days of authentication logs, an attacker who spent the first year quietly building their map can erase their own footprints simply by outliving your retention policy. The forensic team showing up after the ransom note will reconstruct the last three months and call it the whole picture.
The ICO’s investigation found the usual suspects on the defensive side. Weak monitoring of privileged accounts. Inadequate review of remote access. Detection rules built around known malware families rather than behavioral patterns. Multiple alerting opportunities were missed because the alerts weren’t designed to fire on what was actually happening.
Why Cybersecurity Detection Misses Long Dwell Adversaries
Most security operations centers are optimized for noise reduction, not for slow signal. That sounds reasonable until you realize it directly trades against catching patient attackers. A SOC measured on time-to-triage will quietly suppress anything that doesn’t scream. Low-and-slow lateral movement using legitimate Windows tools, credential reuse across business hours, occasional egress to a benign-looking domain, all of these are precisely the things the noise-reduction reflex deletes from the queue.
Brute-force detection illustrates the problem nicely. Most teams alert on a flurry of failed logins from one source. A competent attacker spreads attempts across weeks and rotates source addresses. Your dashboard stays green. The credential spray succeeds against the one service account nobody rotated since 2019, and now they’re inside under a name your tools recognize as legitimate.
Layer on the current threat landscape. AI-assisted exploit development is shortening the gap between vulnerability disclosure and weaponization. Attackers are using large language models to orchestrate multi-stage operations, generate phishing pretexts that survive employee training, and stitch together exploit chains that previously required senior offensive engineering talent. The asymmetry is widening. Defenders who haven’t rethought detection in five years are getting outpaced on both ends, faster attacks at the front door and patient operators already inside.
Concrete Detection Engineering for the Long Tail
Catching a 20-month intrusion requires you to give up the comfortable assumption that the attacker will trip a loud wire. Build detections that assume the adversary is already inside, already credentialed, and already careful. Defense in depth here means stacking multiple weak signals rather than waiting for one strong one.
- Baseline egress, then alert on shape changes. Not just blocked destinations. Watch for slow data buildup to cloud storage, unusual TLS SNI patterns, and beaconing intervals that suggest a scheduler.
- Hunt for legitimate tool abuse. PsExec, WMI, scheduled tasks, RDP, and admin PowerShell are dual-use. Build behavioral baselines per user and per host, then alert on deviation rather than presence.
- Treat dormant accounts as exposure. Any account that hasn’t logged in for 90 days but suddenly authenticates from a new location is a red flag. Service accounts especially.
- Extend log retention beyond your worst-case dwell assumption. If you think 12 months is plausible, keep 18. Cold storage is cheap compared to a forensic blind spot.
- Rotate credentials on a schedule that breaks long-haul persistence. If attackers have valid creds, expire them out from under the operation.
- Run threat hunting as a scheduled discipline, not a quarterly exercise. Assume you missed something, then go look.
Security hardening matters too, and the basics still earn their keep. Phishing-resistant MFA on every account that touches sensitive data. Segmentation between IT and OT networks for industrial environments. Tight egress firewall rules that whitelist known destinations rather than blacklisting bad ones. None of these stop a determined attacker on their own. Together, they raise the cost of staying hidden and increase the odds that one of your weak signals fires.
Incident response readiness is the other half. The South Staffordshire timeline suggests that once detection finally happened, the response was reactive rather than rehearsed. Tabletop exercises that assume long dwell time look different from those that assume same-day discovery. You’ll be reconstructing months of activity from incomplete logs while customer notification clocks tick. Practice that scenario before it’s real.
What the £963,900 Fine Actually Buys
The financial penalty is the part that gets headlines, but it’s not the most interesting part of the ICO ruling. The regulator was specific about what failed. Inadequate monitoring. Missed detection opportunities. Poor management of remote access. This is a roadmap of what regulators in the UK, EU, and increasingly the US will treat as negligence rather than misfortune.
That shift in framing matters. For years, a breach was treated as something that happened to a company. Now it’s increasingly treated as something the company failed to prevent through ordinary diligence. The fine size is calibrated against the volume of exposed records and the duration of the failure, and 20 months is a brutal multiplier. Future enforcement actions will use this case as the comparable.
For sysadmins and security engineers, the operational takeaway is uncomfortable but clear. If your detection capability can’t honestly answer the question “would we catch a careful attacker who’s already inside on day 400,” the answer is to fix that before the regulator does. Threat detection and threat protection aren’t checkbox items anymore. They’re the difference between a contained incident and a seven-figure penalty plus a name in every quarterly threat report for the next two years.
Sources
- Poor security left hackers inside water company network for nearly two years (Help Net Security)
- UK water company allowed hackers to lurk undetected for nearly two years, regulator finds (The Record)
- Hackers Use AI for Exploit Development, Attack Automation (Dark Reading)
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
