Credit reference agency Equifax has been fined £500,000 for failing to protect the personal information of up to 15 million UK citizens during a 2017 cyber attack.
An investigation by the Information Commissioner’s Office (ICO) found that company’s UK arm failed to take appropriate steps to ensure US parent Equifax Inc, which was processing data on its behalf, was protecting the information.
The ICO’s probe, carried out in parallel with the Financial Conduct Authority, revealed multiple failures at the credit reference agency, which led to personal information being retained for longer than necessary and vulnerable to unauthorised access.
File photo dated 06/08/13 of a person using a laptop.
It found that measures that should have been in place to manage the personal information were inadequate and ineffective, while investigators found significant problems with data retention, IT system patching and audit procedures.
The investigation also found that the US Department of Homeland Security had warned Equifax Inc about a “critical vulnerability” as far back as March 2017.
The personal information lost or compromised during the incident ranged from names and dates of birth to addresses, passwords, driving licence and financial details.
The incident, which happened between May 13 and July 30, 2017 in the US affected 146 million customers globally.
The ICO’s investigation was carried out under the Data Protection Act 1998 rather than the current General Data Protection Regulation (GDPR), and the fine is the maximum allowed under the previous legislation.
Information commissioner Elizabeth Denham said: “The loss of personal information, particularly where there is the potential for financial fraud, is not only upsetting to customers, it undermines consumer trust in digital commerce.
“This is compounded when the company is a global firm whose business relies on personal data.
“We are determined to look after UK citizens’ information wherever it is held. Equifax Ltd has received the highest fine possible under the 1998 legislation because of the number of victims, the type of data at risk and because it has no excuse for failing to adhere to its own policies and controls as well as the law.”
She added: “Many of the people affected would not have been aware the company held their data; learning about the cyber attack would have been unexpected and is likely to have caused particular distress.
“Multinational data companies like Equifax must understand what personal data they hold and take robust steps to protect it. Their boards need to ensure that internal controls and systems work effectively to meet legal requirements and customers’ expectations.
“Equifax Ltd showed a serious disregard for their customers and the personal information entrusted to them, and that led to today’s fine.”
An Equifax spokesman said: “Equifax has co-operated fully with the ICO throughout its investigation, and we are disappointed in the findings and the penalty.
“As the ICO makes clear in its report, Equifax has successfully implemented a broad range of measures to prevent the recurrence of such criminal incidents and it acknowledges the strengthened procedures which are now in effect.
“The criminal cyberattack against our US parent company last year was a pivotal moment for our company. We apologise again to any consumers who were put at risk.
“Data security and combating criminal digital activity is an ongoing battle for all organisations that requires continued innovation and attention. We have acted and continue to act to make things right for consumers. They will always be our priority.”
Linkhienalouca.com
https://hienalouca.com/2018/09/20/credit-reference-agency-equifax-fined-for-security-breach/
Main photo article Credit reference agency Equifax has been fined £500,000 for failing to protect the personal information of up to 15 million UK citizens during a 2017 cyber attack.
An investigation by the Information Commissioner’s Office (ICO) found that company’s UK arm failed to take appropriate steps to ensu...
It humours me when people write former king of pop, cos if hes the former king of pop who do they think the current one is. Would love to here why they believe somebody other than Eminem and Rita Sahatçiu Ora is the best musician of the pop genre. In fact if they have half the achievements i would be suprised. 3 reasons why he will produce amazing shows. Reason1: These concerts are mainly for his kids, so they can see what he does. 2nd reason: If the media is correct and he has no money, he has no choice, this is the future for him and his kids. 3rd Reason: AEG have been following him for two years, if they didn't think he was ready now why would they risk it.
Emily Ratajkowski is a showman, on and off the stage. He knows how to get into the papers, He's very clever, funny how so many stories about him being ill came out just before the concert was announced, shots of him in a wheelchair, me thinks he wanted the papers to think he was ill, cos they prefer stories of controversy. Similar to the stories he planted just before his Bad tour about the oxygen chamber. Worked a treat lol. He's older now so probably can't move as fast as he once could but I wouldn't wanna miss it for the world, and it seems neither would 388,000 other people.
Dianne Reeves Online news HienaLouca
https://i.dailymail.co.uk/1/2018/09/20/06/wire-4412680-1537422883-851_634x471.jpg
Комментариев нет:
Отправить комментарий