Two major water businesses in the United States and England disclosed cyber incidents in January 2024, but the evidence was not identical. Veolia North America confirmed ransomware affecting its Municipal Water division and disrupting online bill payment. Southern Water confirmed suspicious activity after the Black Basta group claimed it had stolen data. Neither company reported an interruption to water treatment or supply operations.
The distinction matters: a ransomware incident in a utility’s corporate IT systems is serious, but it is not proof that attackers controlled treatment equipment, altered water chemistry, or shut off customers’ taps.
What happened to Veolia North America?
Veolia North America said its Municipal Water division experienced a ransomware incident during the week before the January 24, 2024 report. The company took affected backend systems and servers offline as a containment measure.
The immediate customer-facing effect was an outage of online bill-payment services. Veolia said the incident appeared confined to internal backend systems and that it had no evidence that water or wastewater treatment operations were affected. It also said personal information belonging to a limited number of individuals might have been compromised.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
No ransomware group had publicly claimed responsibility in the initial reporting. The details were based on Veolia’s statement as reported by SecurityWeek, rather than an independent forensic report.
What happened to Southern Water?
Southern Water serves customers in southern England. At the time, it reported approximately 2.5 million water customers and 4.7 million wastewater customers. The company said it detected suspicious activity on its systems and began an investigation.
Black Basta listed Southern Water on its extortion site and claimed to have taken approximately 750 GB of files. The group alleged that the material included personal information, scans of identity documents and corporate documents, and threatened publication if a ransom was not paid.
Those details remained attacker claims in the available reporting. Southern Water said its services were operating normally and that it had found no evidence that customer-relationship or financial systems had been affected. Its January 2024 notice confirmed suspicious activity, but did not independently validate the alleged data volume, every file shown by Black Basta, or the group’s claim that it had stolen the material.
Rank #2
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Confirmed facts versus claims
| Company | Confirmed by the company | Attacker claim | Customer-facing effect | Reported operational effect | Important unknowns |
|---|---|---|---|---|---|
| Veolia North America, Municipal Water | Ransomware; affected backend systems and servers taken offline; limited personal information may have been compromised | No known public group claim in the initial report | Online bill payment disrupted | No evidence of impact to water or wastewater treatment, according to Veolia | Exact number and categories of affected individuals; ransom status; attack method |
| Southern Water, England | Suspicious activity; investigation underway; services operating normally | Black Basta claimed responsibility and alleged theft of about 750 GB, including identity documents and corporate files | No reported interruption to water or wastewater service | No confirmed treatment or control-system compromise | Whether the alleged files were genuine, the exact amount accessed, encryption, ransom demand and payment status |
Were water supplies interrupted?
There was no reported interruption to water or wastewater treatment operations in either incident. That does not make the events harmless. Veolia customers could not use online bill payment while affected systems were offline, and Southern Water faced a potential privacy, regulatory and extortion problem even while services continued.
Utilities rely on corporate systems for billing, customer communications, procurement, maintenance scheduling, staffing and emergency coordination. The U.S. Environmental Protection Agency identifies possible cyber-incident effects ranging from compromised billing data and websites to interruption of treatment or distribution processes and loss of access to industrial-control systems (EPA incident checklist).
IT, backend systems, OT and SCADA are not the same thing
Corporate IT
Information technology includes email, identity services, billing applications, customer databases, file shares and ordinary business endpoints.
Backend systems
“Backend” is a broad business term. It can include billing databases, enterprise applications and supporting servers. The term alone does not establish whether a treatment plant was reachable.
Recommended Free Tools
Rank #3
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Operational technology
Operational technology monitors or controls physical processes such as pumping, filtration and chemical dosing. A utility may continue operating its plants while its business network is unavailable.
SCADA
Supervisory control and data-acquisition systems are commonly used to monitor and control distributed utility equipment. The available reporting does not establish that either incident reached SCADA or treatment controls.
EPA guidance treats enterprise IT, process-control and communications environments as separate but interconnected parts of a utility. A corporate compromise is therefore not proof of operational sabotage, although weak segmentation can create a path for escalation.
What data may have been exposed?
Veolia
Veolia said information belonging to a limited number of individuals may have been compromised. The initial report did not establish the number of people involved or whether the information included payment-card details, government identifiers or account passwords.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #4
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
Southern Water
Black Basta alleged access to personal information and corporate documents and displayed screenshots said to include identity-document scans. The 750 GB figure came from the attacker and was not independently audited in the available disclosures.
Readers should not treat the following as confirmed without a later company, regulator or law-enforcement notice: a precise affected-person count, payment-card or national-identifier exposure, publication of the alleged files, a ransom amount, or payment of a ransom.
Why water utilities attract ransomware groups
- Utilities combine essential public services with aging infrastructure and constrained budgets.
- They operate mixed environments containing modern cloud systems, legacy business applications and industrial technology.
- Remote access, vendors, internet-facing devices and weak identity controls can expand the attack surface.
- Billing and customer systems hold personal information that can support extortion even when treatment equipment is untouched.
- Prolonged business-system downtime can force manual workarounds and interfere with maintenance, staffing and communications.
- The public importance of water service gives criminals leverage and creates reputational pressure.
These are sector-level risks, not evidence of the access method used against Veolia or Southern Water. The available reports do not establish whether either company was entered through phishing, a vendor, remote-access software or another route.
What customers should do
- Use the utility’s official website or a phone number printed on a prior bill for updates. Do not rely on links in unsolicited incident messages.
- Be alert for phishing emails or texts claiming to offer refunds, restore billing access or verify identity.
- Do not reuse a utility-account password elsewhere, and enable multifactor authentication wherever the utility offers it.
- If the company sends an individual data-compromise notice, follow its instructions and monitor relevant accounts. The initial disclosures did not establish that payment-card or government-identifier data was exposed.
- Keep paying by an alternative official method if online billing is unavailable, and retain confirmation of any payment.
What utilities should learn
On February 21, 2024, CISA, the EPA and the FBI urged water and wastewater organizations to reduce public-internet exposure, inventory IT and OT assets, change default passwords, maintain protected backups, exercise incident-response plans, reduce vulnerabilities and train personnel (joint water-sector guidance).
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Best Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
- Separate corporate IT from treatment and control networks, while controlling the connections between them.
- Require phishing-resistant multifactor authentication for administrators and remote access.
- Maintain offline or otherwise ransomware-resistant backups and test restoration regularly.
- Limit vendor privileges, record remote sessions and remove accounts that are no longer needed.
- Use asset inventories and carefully scoped vulnerability management; indiscriminate active scanning can disrupt sensitive OT devices.
- Prepare communications for customers, regulators, law enforcement, insurers and employees before an incident occurs.
CISA’s StopRansomware Guide emphasizes preparation, isolation, evidence preservation, recovery and coordination. A ransom decision also requires legal and sanctions review; payment does not guarantee deletion of stolen data or restoration of systems.
What the January 2024 incidents show
“Water company hit by ransomware” can describe several different realities. Veolia confirmed a ransomware event with a billing-system consequence and no reported treatment impact. Southern Water confirmed suspicious activity while the most dramatic details came from an unverified Black Basta extortion claim. Neither disclosure demonstrated manipulation of pumps, valves, chemical dosing or SCADA.
The public-interest lesson is not that water utilities are immune when taps keep running. It is that resilience must cover both business systems and physical operations. Billing outages, stolen identity documents, manual work and loss of public confidence can be consequential on their own, while poor segmentation could make a later IT-to-OT escalation more dangerous.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




