Reported incidents ICO fine

Reported incident: Interserve, £4.4 million fine after a phishing email led to a cyber attack

£4.4 million fine · 24 October 2022

Organisation
Interserve Group Limited
Sector
Construction
Regulator
Information Commissioner's Office (ICO)
Announced
24 October 2022
Outcome
£4.4 million fine
Law
GDPR Articles 5(1)(f) and 32; penalty under section 155 of the Data Protection Act 2018

This is a publicly reported regulatory case. The organisation is not, and has not been, one of our clients.

What happened

On 30 March 2020 a phishing email was sent to the accounts team mailbox of Interserve Construction Limited, part of the Interserve group. On 31 March one employee forwarded it to another, who opened it on 1 April 2020. Extracting the attached ZIP file installed malware on the employee's workstation. Interserve's endpoint protection tool reported that it had automatically removed malware files, but Interserve took no further action to check that all of the malware had gone.

The attacker kept access. On 1 and 2 May 2020 they used tools to compromise 283 systems and 16 accounts, 12 of them privileged accounts, and used a compromised account to run a script that uninstalled Interserve's anti-virus. They compromised four HR databases, and the personal data on them was encrypted and made unavailable. Some of that data was not available again until July 2020.

The data related to up to 113,000 current and former employees. It included contact details, National Insurance numbers, bank account details, salary, dates of birth and details of dependants, as well as special category data about ethnic origin, religion, disability, sexual orientation and health. Interserve said there was no evidence that data was taken. The ICO noted that the measures that could have detected this, such as firewall filtering and endpoint logging, were only put in place after the incident.

Interserve discovered the attack during a routine maintenance check on 2 May 2020. It told the National Cyber Security Centre the same day, and reported the breach to the ICO and the National Crime Agency on 5 May 2020. The ICO's penalty notice is dated 19 October 2022 and the fine was announced on 24 October 2022. In the ICO's news release, John Edwards, the UK Information Commissioner, said: "The biggest cyber risk businesses face is not from hackers outside of their company, but from complacency within their company."

What the regulator found

Lessons for small organisations

Want to know where you stand?

We assess your public web and email surface and send you a written report. No charge, no obligation.

Book a free audit

← All reported incidents