- Organisation
- Interserve Group Limited
- Sector
- Construction
- Regulator
- Information Commissioner's Office (ICO)
- Announced
- 24 October 2022
- Outcome
- £4.4 million fine
- Law
- GDPR Articles 5(1)(f) and 32; penalty under section 155 of the Data Protection Act 2018
This is a publicly reported regulatory case. The organisation is not, and has not been, one of our clients.
What happened
On 30 March 2020 a phishing email was sent to the accounts team mailbox of Interserve Construction Limited, part of the Interserve group. On 31 March one employee forwarded it to another, who opened it on 1 April 2020. Extracting the attached ZIP file installed malware on the employee's workstation. Interserve's endpoint protection tool reported that it had automatically removed malware files, but Interserve took no further action to check that all of the malware had gone.
The attacker kept access. On 1 and 2 May 2020 they used tools to compromise 283 systems and 16 accounts, 12 of them privileged accounts, and used a compromised account to run a script that uninstalled Interserve's anti-virus. They compromised four HR databases, and the personal data on them was encrypted and made unavailable. Some of that data was not available again until July 2020.
The data related to up to 113,000 current and former employees. It included contact details, National Insurance numbers, bank account details, salary, dates of birth and details of dependants, as well as special category data about ethnic origin, religion, disability, sexual orientation and health. Interserve said there was no evidence that data was taken. The ICO noted that the measures that could have detected this, such as firewall filtering and endpoint logging, were only put in place after the incident.
Interserve discovered the attack during a routine maintenance check on 2 May 2020. It told the National Cyber Security Centre the same day, and reported the breach to the ICO and the National Crime Agency on 5 May 2020. The ICO's penalty notice is dated 19 October 2022 and the fine was announced on 24 October 2022. In the ICO's news release, John Edwards, the UK Information Commissioner, said: "The biggest cyber risk businesses face is not from hackers outside of their company, but from complacency within their company."
What the regulator found
- Between 18 March 2019 and 1 December 2020 Interserve failed to use appropriate technical and organisational measures to keep personal data secure, breaching GDPR Articles 5(1)(f) and 32.
- Interserve did not properly investigate the initial malware alert or check that all of the malware had been removed.
- Personal data was held on 18 servers running Server 2003 R2 and 22 running Server 2008 R2. Both had reached end of life before the attack, in July 2015 and January 2020, and Interserve had not carried out any formal risk assessment of using unsupported systems.
- The outdated SMB version 1 network protocol was in widespread use.
- Endpoint protection was weak. Most servers were not running the latest anti-virus protection, host-based firewalls were not enabled, there were no application allow or deny lists, and macros were not blocked on the first computer to be compromised.
- Interserve could not show any penetration testing in the two years before the attack.
- Over 280 users were in the domain administrator group, so a large number of accounts had wide control of the network.
- One of the two employees who received the phishing email had not done data protection training. Interserve had adopted appropriate security policies and standards, but they were not effectively implemented or followed.
- The ICO noted that Interserve had reported two earlier personal data breaches in April and May 2019, after which it was referred to the ICO's security guidance. It took account of Interserve's cooperation and its remediation work, completed by 1 December 2020, but found insufficient evidence that Interserve could not pay. The fine stayed at £4.4 million after Interserve's representations.
Lessons for small organisations
- When anti-virus or another security tool reports a threat, treat it as a reason to investigate. Check the device properly, or ask your IT provider to, and keep a note of what was checked and what was found.
- Replace or remove any computer, server or software that no longer receives security updates. Keep a list of your devices with their end of support dates, and plan upgrades before support stops.
- Keep administrator access to a very small number of named people, and have them use a separate admin account only when they need it, not for everyday email and browsing.
- Give everyone who handles email short, regular training on phishing, including new starters, and make it easy to report a suspicious message instead of forwarding it to a colleague.
- Check that your security policies work in practice. Turn on firewalls, block macros in documents from the internet, and have your defences tested from time to time, because a written policy that nobody follows will not protect you.
Want to know where you stand?
We assess your public web and email surface and send you a written report. No charge, no obligation.
Book a free auditSources
- ICO: 'Biggest cyber risk is complacency, not hackers' (Interserve fined £4.4m)
- ICO: Interserve Group Limited (enforcement action)
- ICO: Penalty notice, Interserve Group Limited, 19 October 2022 (copy hosted by ISMG)
- Hunton Andrews Kurth: UK Information Commissioner's Office Fines Construction Company £4.4 Million for Breach of Security Obligations