Case Studies

Firm fined £150k for data breach

by Mark Rowe

An online travel services company, has been served a £150,000 fine by the Information Commissioner’s Office (ICO) after what the data protection watchdog termed a serious breach of the Data Protection Act. Think W3 Limited showed thousands of people’s details to a malicious hacker.

The ICO has reported that the company was hacked in December 2012 after using insecure coding on the website of a subsidiary business, Essential Travel Ltd. The hacker extracted a total of 1,163,996 credit and debit card records. Of these records 430,599 were identified as current and 733,397 as expired. Cardholder details had not been deleted since 2006 and there had been no security checks or reviews since the system had been installed.

Stephen Eckersley, Head of Enforcement at the Cheshire-based ICO, said: “This was a staggering lapse that left more than a million holiday makers’ personal details exposed to a malicious hacker. Data security should be a top priority for any business that operates online. Think W3 Limited accepted liability for failing to keep their customers’ personal data secure; failing to test their security and failing to delete out-of-date information.

“The public’s awareness of the importance of data protection is rising all the time. Ignorance from data controllers is no excuse. They must take active steps to ensure the personal data they are responsible for is kept safe or face enforcement action and the resulting reputational damage.”

Related News

  • Case Studies

    VMS in port

    by Mark Rowe

    A case study of IP video management software (VMS) in use by Faxaports, The Associated Icelandic Ports, for security, handling cargo and…

  • Case Studies

    Guide by watchdog

    by msecadm4921

    The Information Commissioner’s Office (ICO) has published a new guide for small and medium sized businesses, showing steps they can take to…

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing