Unavoidably Secure

Reported incidents

Real enforcement cases from the Information Commissioner's Office, and what each one means for a dental practice, care provider or small firm. None of these organisations are our clients.

Every case is checked against the ICO's own penalty notice or announcement, and each page lists its sources. If you spot anything out of date, email support@unavoidablysecure.com and we will correct it.

16 April 2025 · £60,000 fine ICO fine

DPP Law, £60,000 fine after a brute-force attack

In June 2022 an attacker got into the network of DPP Law, a law firm based in Bootle, through an administrator account that had no MFA and full rights across the network. 32.4GB of data about 791 people was stolen and later published on the dark web. DPP reported the breach to the ICO 43 days after the attack. The ICO fined it £60,000 for poor account security and late reporting.

The lesson: Audit every account, remove the ones you no longer need and protect the rest with MFA, including service accounts. If an attack cuts off access to personal data, treat it as a possible breach and assess it within 72 hours.

Read the case
16 January 2024 · £150,000 and £100,000 fines (£250,000 in total) PECR fine

Poxell Ltd and Skean Homes Ltd, £250,000 in fines for calls to TPS numbers

On 16 January 2024 the ICO announced two separate PECR fines against home improvement firms: £150,000 for Poxell Ltd and £100,000 for Skean Homes Ltd. In 2022 they made about 3.26 million marketing calls between them to numbers registered with the Telephone Preference Service, without properly identifying themselves. Poxell used multiple phone numbers to avoid detection. Skean used false trading names and blamed a lead generator.

The lesson: Screen every call list against the TPS and your own do-not-call list, and always say who is calling. Letting a third party use your lines does not move the responsibility off you.

Read the case
12 January 2024 · £140,000 fine PECR fine

HelloFresh, £140,000 fine for 80.9 million unlawful marketing messages

On 12 January 2024 the ICO fined HelloFresh £140,000 under PECR. Between August 2021 and February 2022 it sent 79.8 million marketing emails and 1.1 million texts without valid consent. Its opt-in box mentioned email but not texts, was bundled with an age confirmation, and did not tell customers they could be marketed to for up to 24 months after cancelling.

The lesson: Marketing consent must name each channel you use and stand apart from anything else the customer is agreeing to. Tell people how long you will market to them, and make opting out work quickly.

Read the case
24 October 2022 · £4.4 million fine ICO fine

Interserve, £4.4 million fine after a phishing email led to a cyber attack

In March 2020 a phishing email reached an Interserve accounts mailbox. An employee opened the attachment and installed malware. The anti-virus reported removing it, but nobody checked. A month later the attacker compromised 283 systems and 16 accounts, and HR databases holding data on up to 113,000 current and former employees were encrypted. The ICO fined Interserve Group Limited £4.4 million in October 2022.

The lesson: Treat every security alert as a reason to investigate, not a problem already solved, and replace any system that no longer receives security updates.

Read the case
10 March 2022 · £98,000 fine ICO fine

Tuckers Solicitors, £98,000 fine after a ransomware attack

In August 2020 a ransomware attack on Tuckers Solicitors, a London criminal defence firm, encrypted 972,191 files on an archive server. The attacker took 60 court bundles, including witness statements and medical files, and released them on underground marketplaces. The ICO found there was no MFA on remote access, a critical patch was installed more than four months late and the archive was not encrypted. It fined the firm £98,000.

The lesson: Use MFA on all remote access, install critical security updates within 14 days and encrypt archived client files. Tuckers fell short on all three.

Read the case
8 July 2021 · £25,000 fine ICO fine

Mermaids, £25,000 fine after an email group was left publicly viewable

In June 2019 a Sunday Times journalist told a Mermaids service user that her personal data could be read online. An internal email group the charity set up in 2016 on Groups.IO had been left publicly viewable and indexed by search engines. Around 780 pages of emails about 550 people, some of them children, were exposed for nearly three years. The ICO fined the charity £25,000 in July 2021.

The lesson: Check the privacy settings of every online tool that holds personal data instead of trusting the default, and close down old groups and accounts properly rather than leaving them dormant.

Read the case