The TalkTalk fine was imposed after an investigation by the ICO found that three employees from Wipro, an outsourcing company, hired by TalkTalk to provide customer service and technical support, gained unauthorised access to customer data.
In 2014 40 Wipro employees had ‘unjustifiably wide-ranging’ access to between 25,000 and 50,000 customers, according to the ICO. Three of those accounts were then used to illegally access data of up to 21,000 customers.
TalkTalk customers complained of calls from scammers identifying themselves as engineers from the telecoms giant. Scammers reportedly had information only accessible to TalkTalk, including details of previous support calls, and used this to gain the customer’s trust.
A spokesperson from TalkTalk said: “We notified the ICO in 2014 of our suspicions that a small number of employees at one of our third-party suppliers were abusing their access to non-financial customer data.
“We informed our customers at the time and launched a thorough investigation, which has led to us withdrawing all customer service operations from India.”
The £100,000 TalkTalk fine takes the firm’s penalties for data breaches to £500,000. This includes a £400,000 fine for a hacking attack in October 2015 in which the data of 157,000 customers was compromised.
The UK’s Information Commissioner, Elizabeth Denham, said: “TalkTalk may consider themselves to be the victims here. But the real victims are the 21,000 people whose information was open to abuse by the malicious actions of a small number of people.
“TalkTalk should have known better and they should have put their customers first.”





