If proof was needed that poor data protection is bad for the corporate wallet, two examples have demonstrated that substantial fines face those organisations that have lax data security.
The international hotel group Marriott is to be fined almost £100m by the Information Commissioner’s Office after hackers stole the records of 339 million guests.
In November, Marriott International, the parent company of hotel chains including W, Westin, Le Méridien and Sheraton, admitted that personal data including credit card details, passport numbers and dates of birth had been stolen in a colossal global hack of guest records.
The ICO, which is proposing a £99.2m fine for Marriott, said that about 30 million of the hacked guest records related to residents of 31 countries in the European Economic Area. Seven million related to UK residents.
Marriott said it would appeal against the fine.
The UK’s data watchdog has also announced plans to fine the airline British Airways a record £183 million over last year’s data breach.
The Information Commissioner’s Office (ICO) said that “poor security arrangements” at the company lead to the breach of credit card information, names, addresses, travel booking details, and logins for around 500,000 customers. The fine would be the largest the ICO has ever issued, BBC News reports, far more than the £500,000 fine against Facebook for the Cambridge Analytica scandal that affected millions. British Airways will now have 28 days to appeal the ruling before it is made final.
In a statement, the Information Commissioner Elizabeth Denham said that the loss of personal data is “more than an inconvenience” and said that companies should take appropriate steps “to protect fundamental privacy rights.”
Europol Releases Latest IOCTA Report
Each year, Europol’s European Cybercrime Centre (EC3) publishes the Internet Organised Crime Threat Assessment (IOCTA), its flagship strategic report on key findings and emerging threats and developments in cybercrime — threats that impact governments, businesses and citizens in the EU.read more
European Cybersecurity Month 2019 Is launched
October marks the kick-off of the European Cybersecurity Month (ECSM), coordinated by the European Union Agency for Cybersecurity (ENISA), the European Commission and supported by the Member States. This campaign will focus on expanding awareness about cybersecurity to citizens across Europe.read more
Remote Desktop Attacks Increasing
The Remote Desktop Protocol (RDP) is being used by cyberattackers to penetrate and extract data from a network before introducing their malicious software to perform internal reconnaissance, according to a new Vectra 2019 Spotlight Report on RDP.read more
LexisNexis Report On Cybercrime Has Shock Figures
LexisNexis Risk Solutions has released at the Digital Identity Summit its Cybercrime Report providing a comprehensive view into the shifting global fraud landscape from January 2019 through June 2019. During this period, the LexisNexis Digital Identity Network recorded 16.4 billion transactions, of which 277 million were human-initiated attacks, a 13 per cent increase over the second half of 2018.read more