Site navigation

ICO Fines Law Firm £60,000 Following Cyber-attack

Elizabeth Greenberg

,

ico law firm fine
“Our investigation demonstrates we will hold organisations to account for a failure to notify where there was a clear obligation to do so at the time of the underlying incident,” ICO interim director of enforcement and investigations Andy Curry said. 

The Information Commissioner’s Office has fined a law firm £60,000 following a cyber-attack that leaked highly sensitive data which was published on the dark web.

DPP Law, based in Merseyside, was found by the ICO to have failed in its responsibilities to secure the personal information it held.

This failure – namely its lack of multi-factor authentication on one of its databases – allowed hackers to gain access to DPP’s network and steal large volumes of data.

DPP specialises in law related to crime, military, family fraud, sexual offenses, and actions against the police. The very nature of this work means that it is responsible for both highly sensitive and special category data, including legally privileged information.

As the information stolen by the attackers revealed private details about identifiable individuals, DPP has a responsibility under the law to ensure it is properly protected, the ICO said.

The cyber-attack took place in June 2022, and affected DPP’s IT systems for over a week. A third-party consulting firm established that a brute force attempt gained access to the administrator account that was used to access a legacy case management system.

The attackers could then move laterally across DPP’s network and take over 32GB of data, a fact DPP only became aware of when contacted by the National Crime Agency (NCA) that the data had been shared on the dark web.

DPP did not consider that the loss of access to personal information constituted a personal data breach, so did not report the incident to the ICO until 43 days after they became aware of it.


Recommended reading


“Our investigation revealed lapses in DPP’s security practices that left information vulnerable to unauthorised access,” Andy Curry, interim director of enforcement and investigations, said.

“In publicising the errors which led to this cyber attack, we are once again highlighting the need for all organisations to continually assess their cybersecurity frameworks and act responsibly in putting in place robust measures to prevent similar incidents.

“Our investigation demonstrates we will hold organisations to account for a failure to notify where there was a clear obligation to do so at the time of the underlying incident.

“Data protection is not optional. It is a legal obligation, and this penalty should serve as a clear message: failure to protect the information people entrust to you carries serious monetary and reputational consequences.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data