Interserve hit with £4.4m fine after cyber attack

Grant Prior 1 year ago
Share

Interserve Group Ltd has been fined £4.4m by the Information Commissioner’s Office (ICO) for failing to keep personal information of its staff secure.

The fine follows a breach of data protection law in May 2020 when the company failed to put appropriate security measures in place to prevent the cyber attack, which enabled hackers to access the personal data of up to 113,000 employees through a phishing email.

The compromised data included personal information such as contact details, national insurance numbers, and bank account details.

The ICO said: “An Interserve employee forwarded a phishing email, which was not quarantined or blocked by the company’s system, to another employee who opened it and downloaded its content.

“This resulted in the installation of malware onto the employee’s workstation.

“The company’s anti-virus software quarantined the malware and sent an alert, but Interserve failed to thoroughly investigate the suspicious activity. If they had done so, Interserve would have found that the attacker still had access to the company’s systems.

“The attacker subsequently compromised 283 systems and 16 accounts, as well as uninstalling the company’s anti-virus solution. Personal data of up to 113,000 current and former employees was encrypted and rendered unavailable.

“The ICO investigation found that Interserve failed to follow-up on the original alert of a suspicious activity, used outdated software systems and protocols, and had a lack of adequate staff training and insufficient risk assessments, which ultimately left them vulnerable to a cyber attack.”

The ICO issued Interserve with a ‘notice of intent’ – a legal document that precedes a potential fine. The provisional fine amount was set at £4.4m. Having carefully considered representations from Interserve, no reductions were made to the final fine amount.

Interserve plc went into a pre-pack administration in March 2019 and was rebranded as Interserve Group. A break-up followed with Interserve’s facilities management business sold to Mitie in December 2020 and RMD Kwikform sold in October 2021 to Altrad.

In March 2021 Interserve rebranded its construction and engineering business as Tilbury Douglas.

An Interserve statement said: ‘”Interserve has worked extensively with the Information Commissioner’s Office (ICO) and the National Cyber Security Centre since first reporting the cyber incident in May 2020.

“Interserve strongly disputes that its staff and the company’s response were in any way complacent.

“Interserve took extensive steps to resolve the incident, engaging leading cyber response companies, and made significant investments across its operating companies to mitigate the potential impacts of the cyber incident on its past and present staff.

“It also sought to reduce the risk of future incidents and successfully facilitate the safe and effective ongoing operations of Tilbury Douglas and the facilities management business acquired by Mitie Group PLC.

“Interserve will continue to prioritise the interests of its past and present staff, counterparties and other stakeholders while engaging with the ICO to resolve their investigations”

Latest news

Geoffrey Osborne files administration notice

Contractor in talks to save parts of the business
1 day ago

RG Group signs £121m Newcastle rental homes job

Developer Olympian Homes advances 519 flats plan at Pottery Lane site
1 day ago

Winners named for £260m Manchester Uni framework

B&K, Henry Bros, Graham, Robertson and Vinci among new line-up
1 day ago

Shed specialist Benniman rides out market lull

Worcestershire warehouse builder says industrial and logistics work is picking up again
1 day ago

Another contractor cleared after high profile immigration raid

Adana Construction employees were working legally on site swooped on by Home Office
1 day ago

McAleer & Rushe wants to meet new London suppliers

Contractor holding Meet the Buyer event in London: Register now
1 day ago

McAlpine signs £500m Broadgate dual towers deal

Work to start on iconic 36-storey and 21-storey towers
2 days ago

Worker rescued from collapsed four metre deep trench

Fire crews take six hours to save trapped builder near Blackwall Tunnel
2 days ago

Gove puts another major building scheme on hold

Secretary of State starts another planning fight after M&S defeat
3 days ago

Greenwich University tenders £300m framework

Up to five firms will carry out upgrade and newbuild work at three campuses
2 days ago

Work starts on Manchester 26-storey Obsidian tower

Contractor Domis starts Salboy's 10th Manchester scheme in seven years
2 days ago

Race for £1.3bn West Midlands social homes framework

The Community Housing Group reboots tender race for new build housing
2 days ago

Delancey submits £400m King’s Cross lab plans

200,000 sq ft lab/office project will be built above railway and tube tunnels just 4.5m below
3 days ago

Winners revealed for £150m fire safety framework

New deal will help organisations comply with the Building Safety Act
2 days ago

Sellar plans £500m City tower next to Walkie-Talkie

Consultation starts on London 60 Gracechurch Street tower
3 days ago

Severfield ends year on high with record order book

Orders top £500m with strong future pipeline of opportunities ahead
3 days ago

Second senior director exits National Highways

Commercial director Malcolm Dare set to move on to new role
3 days ago

New scheme fuels London lab building boom

Plans in for 160,000 sq ft Whitechapel scheme near Royal London hospital
3 days ago

Contract race starts for next £155m section of A9 dualling

Prior Information Notice published for Tay Crossing to Ballinluig stretch
4 days ago

£55m Sheffield build-to-rent scheme approved

Demolition to start later this year for 158-flat Sheffield Garden project
4 days ago

London back as most expensive place to build in world

Capital leapfrogs Geneva to top costliest construction rankings
4 days ago

Gas supplier Regent to buy TClarke for £90m

£491m turnover listed building services specialist to be sold
4 days ago

Steel contractor Billington launches into bridge market

Steelwork firm hires staff from failed architectural and bridge specialist SH Structures
4 days ago

McGee employees benefit from rise in profits

Pre-tax profit doubles boosting payouts for Employee Ownership Trust
4 days ago

Lendlease veteran is latest new McAlpine director

Paul Sims joins as Operations Director after 40 years at rival contractor
5 days ago

Costain signs site labour supply deal with four firms

Contractor to use only a quartet of providers for temporary labour supply
4 days ago

BAM go-ahead for Leeds 200,000 sq ft office

Latitude Yellow will complete final plot at Doncaster Monk Bridge site
5 days ago

VolkerFitzpatrick wins £30m logistics job

Latest deal to build five distribution units for Prologis UK
5 days ago

Trio win new Scape utilities consultancy framework

Perfect Circle, AtkinsRéalis and Arcadis win places on
4 days ago

Precast firm FP McCann cleared after immigration raid

Home Office takes no action after public raid on construction site
5 days ago

Contractor services