TalkTalk (LON:TALK) has been fined a record £400,000 for failing to implement the "most basic" cyber security measures by The Information Commissioner's Office (ICO).
The attack in October last year was among the most high profile corporate breaches of internet security and saw the theft of personal data from nearly 157,000 customers.
Alarmingly, in nearly 16,000 cases, the attacker was able to steal bank account details.
Six people, all under 21, have been arrested as part of the ongoing investigation.
The financial punishment is the largest yet imposed by the ICO, which could have delivered a maximum fine of £500,000.
In its findings, the ICO explained that TalkTalk had been lax in enforcing proper security and that software, which held details of customers inherited from the 2009 takeover of a rival firm Tiscali, was out of date.
The hackers got the details by attacking three vulnerable web pages, using a well-known hacking technique called SQL injection.
The incident caused chaos last year and sent shudders through the telecoms and IT world.
After the attack, there was a ransom demand from a company purporting to have perpetrated the security breach, according to reports.
Police, namely London's Metropolitan Police Cyber Crime Unit, instantly launched a probe.
Information Commissioner Elizabeth Denham said... hacking was wrong, but that it was not an excuse for companies to abdicate their security obligations.
She added: "Today's record fine acts as a warning to others that cyber security is not an IT issue, it is a boardroom issue."
TalkTalk took a financial hit - £42mln in fact, although the impact turned out to be less than first thought.
Shares added 1.34% to 212.2p.