Interserve PLC (LSE:IRV) has been fined £4.4mln by the Information Commissioner’s Office (ICO) after a phishing email allowed hackers to access the information of up to 113,000 current and former employees at the construction company.
Bank account details and national insurance numbers were among the information that was leaked in the cyber-attack two years ago, which also included other personal details, such as ethnicity, religion and sexual orientation of employees.
At the time, Interserve ran an outsourcing businesses, with the Ministry of Defence as a client.
According to the ICO, outdated software, protocols and a lack of staff training as well as risk assessments on Interserve's part amounted to a breech in data protection law.
UK information commissioner John Edwards said: “This data breach had the potential to cause real harm to Interserve’s staff, as it left them vulnerable to the possibility of identity theft and financial fraud.
“If your business doesn’t regularly monitor for suspicious activity in its systems and fails to act on warnings or doesn’t update software and fails to provide training to staff, you can expect a similar fine from my office.”