- Organisation
- Tuckers Solicitors LLP
- Sector
- Legal services (criminal defence law firm)
- Regulator
- Information Commissioner's Office (ICO)
- Announced
- 10 March 2022
- Outcome
- £98,000 fine
- Law
- GDPR Article 5(1)(f) (the EU GDPR, which applied at the time)
This is a publicly reported regulatory case. The organisation is not, and has not been, one of our clients.
What happened
Tuckers Solicitors LLP is a criminal defence law firm based in London, with offices in other parts of England. It told the ICO it held information about more than 60,000 clients.
On 24 August 2020 Tuckers became aware of a ransomware attack on its systems. The attacker encrypted 972,191 files on an archive server, more than 24,700 of them court bundles. The backups were encrypted too. Most of the personal data the firm held was on other servers and systems that were not affected.
The attacker took 60 court bundles, 15 from criminal cases and 45 from civil cases, and released them on underground data marketplaces. The bundles included medical files, witness statements, the names and addresses of witnesses and victims, and details of alleged crimes. Some of the people involved were particularly vulnerable, including children.
On 25 August 2020 Tuckers decided that the attack was a personal data breach and reported it to the ICO the same day. Neither Tuckers nor the specialists investigating could establish exactly how the attacker got into the network. Tuckers told the ICO that the system it used to give staff remote desktops was at the centre of the attack.
The ICO's monetary penalty notice is dated 28 February 2022. The £98,000 fine was made public on 10 March 2022.
What the regulator found
- Tuckers breached Article 5(1)(f) of the GDPR, the security principle, between 25 May 2018 and 25 August 2020. The EU GDPR applied at the time of the attack, and the ICO was the supervisory authority.
- There was no MFA on the remote access system, even though Tuckers' own data protection policy required two-factor authentication where available. The ICO said the firm should not have allowed access to its network with only a single username and password, and that MFA was a comparatively low-cost measure with many compatible products available.
- The ICO said exploiting a single username and password is a common attack method and was likely to be one of two possible ways the attacker got in, and that the lack of MFA created a substantial risk.
- A critical vulnerability, rated 9.8 out of 10, had a patch available from January 2020. Tuckers installed it in June 2020, more than four months later. The ICO noted that Cyber Essentials expects high and critical patches to be applied within 14 days, and said the delay was a significant deficiency even if the attacker did not use it.
- The archived court bundles were stored unencrypted, in plain text. Given how sensitive they were, the ICO said Tuckers should not have stored them that way.
- Tuckers had been assessed against Cyber Essentials in October 2019 and failed to meet crucial parts of it.
- The ICO was also concerned about compliance with Articles 5(1)(e), 25 and 32, including court bundles kept beyond the firm's seven-year retention period, some of which were stolen in the attack. These concerns did not form the basis of the penalty.
- In setting the fine the ICO took account of Tuckers' financial position, IT staff illness and shortages, and its work protecting vulnerable people. It gave no reduction for the security improvements made after the attack, because those should have been in place already.
Lessons for small organisations
- Put MFA on every way into your systems from outside, including remote desktops, VPNs and email. A username and password on their own are not enough.
- Install high and critical security updates within 14 days, as Cyber Essentials requires. Ask your IT provider to confirm each month that this has been done.
- Encrypt stored archives of client or patient records, not just laptops and phones. Old files are still sensitive, and encryption makes stolen data much harder to use.
- Follow your retention schedule and delete records when the period ends. Data you no longer hold cannot be stolen.
- Keep at least one backup that ransomware on your main network cannot reach, for example an offline or immutable copy, and test that you can restore from it.
Want to know where you stand?
We assess your public web and email surface and send you a written report. No charge, no obligation.
Book a free audit