Interserve hit with £4.4m fine after cyber attack

Grant Prior 3 years ago
Share

Interserve Group Ltd has been fined £4.4m by the Information Commissioner’s Office (ICO) for failing to keep personal information of its staff secure.

The fine follows a breach of data protection law in May 2020 when the company failed to put appropriate security measures in place to prevent the cyber attack, which enabled hackers to access the personal data of up to 113,000 employees through a phishing email.

The compromised data included personal information such as contact details, national insurance numbers, and bank account details.

The ICO said: “An Interserve employee forwarded a phishing email, which was not quarantined or blocked by the company’s system, to another employee who opened it and downloaded its content.

“This resulted in the installation of malware onto the employee’s workstation.

“The company’s anti-virus software quarantined the malware and sent an alert, but Interserve failed to thoroughly investigate the suspicious activity. If they had done so, Interserve would have found that the attacker still had access to the company’s systems.

“The attacker subsequently compromised 283 systems and 16 accounts, as well as uninstalling the company’s anti-virus solution. Personal data of up to 113,000 current and former employees was encrypted and rendered unavailable.

“The ICO investigation found that Interserve failed to follow-up on the original alert of a suspicious activity, used outdated software systems and protocols, and had a lack of adequate staff training and insufficient risk assessments, which ultimately left them vulnerable to a cyber attack.”

The ICO issued Interserve with a ‘notice of intent’ – a legal document that precedes a potential fine. The provisional fine amount was set at £4.4m. Having carefully considered representations from Interserve, no reductions were made to the final fine amount.

Interserve plc went into a pre-pack administration in March 2019 and was rebranded as Interserve Group. A break-up followed with Interserve’s facilities management business sold to Mitie in December 2020 and RMD Kwikform sold in October 2021 to Altrad.

In March 2021 Interserve rebranded its construction and engineering business as Tilbury Douglas.

An Interserve statement said: ‘”Interserve has worked extensively with the Information Commissioner’s Office (ICO) and the National Cyber Security Centre since first reporting the cyber incident in May 2020.

“Interserve strongly disputes that its staff and the company’s response were in any way complacent.

“Interserve took extensive steps to resolve the incident, engaging leading cyber response companies, and made significant investments across its operating companies to mitigate the potential impacts of the cyber incident on its past and present staff.

“It also sought to reduce the risk of future incidents and successfully facilitate the safe and effective ongoing operations of Tilbury Douglas and the facilities management business acquired by Mitie Group PLC.

“Interserve will continue to prioritise the interests of its past and present staff, counterparties and other stakeholders while engaging with the ICO to resolve their investigations”

Latest news

Mace lands latest 30-storey City of London tower

85 Gracechurch Street near Leadenhall Market to be transformed
38 minutes ago

Vinci gets go-ahead for £250m Stockport 8 scheme

Contractor to start first phase of 435 net zero homes next year
9 minutes ago

£80m bid race to convert Oxford Debenhams into labs

Crown Estate advance plan to convert former six storey department store
10 minutes ago

Bennett steps-in to finish Guinness Covent Garden brewery

Original fit-out contractor Beck Interiors fell into administration
34 minutes ago

Work-to-rule set to hit Sellafield clean-up

Action by 1,500 construction workers across 34 contractors
4 minutes ago

Aureos breaks ground on £45m Howden Relief Road

Yorkshire road will pave way for 2,000-home scheme
8 minutes ago

Oxford United win green light for £150m all-electric stadium

Planners back 16,000-seat Kidlington ground with hotel, plaza and community hub
3 days ago

Demolition record as eight cooling towers come down

Watch Brown & Mason set record at Cottam Power Station
4 days ago

Hitachi Energy named for EGL3 converter station deal

Firm to build major HVDC converter stations in Aberdeenshire and West Norfolk
3 days ago

PAS NW secures landmark £20m civils deal in Lancashire

Groundworks firm wins infrastructure for 429-home Wain Homes scheme
3 days ago

Subcontractors wanted for jobs across the South West

Register now for latest Constructionline event in Bristol
3 days ago

Profits double at Octavius as road and rail work grows

Recent acquisitions add to turnover growth at infrastructure specialist
4 days ago

Quarterly construction output growth masks orders slide

New orders down by over 8% driven by fall in infrastructure and offices
4 days ago

Vinci UK swings back into profit after group restructure

£166m cash injected to strengthen building and facilities operations balance sheets
5 days ago

Staged procurement to make comeback as pricing risk bites

Developers turn to staged deals to control costs on big-ticket commercial jobs
4 days ago

McGee profit halves as project start delays hit

Revenue up 24% but profits fall on higher carry costs
4 days ago

Vistry to deliver 2,300 homes at Rugeley power station site

139-acre brownfield site has already been extensively remediated
4 days ago

Andrew Scott wins role on Swansea’s next big office build

Contractor appointed for detailed design of 800-desk city centre hub.
4 days ago

Knights Brown to start £29m Poole flood wall job

1.5km barrier to protect homes and unlock regeneration plans
4 days ago

Kier lands £16m first ECI job with Southern Water

Design deal covers nitrogen cut and UV upgrade at Hampshire wastewater sites
5 days ago

Watkin Jones seals deal on 200-bed student scheme

Bristol project will involve four brick buildings rising to seven storeys
5 days ago

Severfield brings in new CEO from Laing O’Rourke ranks

Everton Stadium job chief Paul McNerney to take the helm in the autumn
5 days ago

Balfour hits 3% construction margin target

Profit target finally reached after eight years
5 days ago

Network Rail launches £240m OLE steelworks framework race

Deal to supply overhead line equipment for electrification schemes
5 days ago

Briefing starts for £8bn highways maintenance shake-up

National Highways launches early talks on next-generation regional roads upkeep
5 days ago

Plant hirer Lynch launches labour supply division

Workers now available to Tier 1 and Tier 2 infrastructure contractors
5 days ago

Kori lands latest £17m care home contract

Work to start on site in south west London next month
6 days ago

£70m Bristol student job finally gets Gateway 2 approval

Student developer Unite to progress two big schemes
6 days ago

Government unveils 10 new construction technical colleges

£100m plan to train 40,000 skilled trades by 2029 gets off the ground
6 days ago

McLaren lands London School of Economics £100m revamp

Central London job will be largest Passivhaus retrofit building in the UK
6 days ago