Interserve hit with £4.4m fine after cyber attack

Grant Prior 3 years ago
Share

Interserve Group Ltd has been fined £4.4m by the Information Commissioner’s Office (ICO) for failing to keep personal information of its staff secure.

The fine follows a breach of data protection law in May 2020 when the company failed to put appropriate security measures in place to prevent the cyber attack, which enabled hackers to access the personal data of up to 113,000 employees through a phishing email.

The compromised data included personal information such as contact details, national insurance numbers, and bank account details.

The ICO said: “An Interserve employee forwarded a phishing email, which was not quarantined or blocked by the company’s system, to another employee who opened it and downloaded its content.

“This resulted in the installation of malware onto the employee’s workstation.

“The company’s anti-virus software quarantined the malware and sent an alert, but Interserve failed to thoroughly investigate the suspicious activity. If they had done so, Interserve would have found that the attacker still had access to the company’s systems.

“The attacker subsequently compromised 283 systems and 16 accounts, as well as uninstalling the company’s anti-virus solution. Personal data of up to 113,000 current and former employees was encrypted and rendered unavailable.

“The ICO investigation found that Interserve failed to follow-up on the original alert of a suspicious activity, used outdated software systems and protocols, and had a lack of adequate staff training and insufficient risk assessments, which ultimately left them vulnerable to a cyber attack.”

The ICO issued Interserve with a ‘notice of intent’ – a legal document that precedes a potential fine. The provisional fine amount was set at £4.4m. Having carefully considered representations from Interserve, no reductions were made to the final fine amount.

Interserve plc went into a pre-pack administration in March 2019 and was rebranded as Interserve Group. A break-up followed with Interserve’s facilities management business sold to Mitie in December 2020 and RMD Kwikform sold in October 2021 to Altrad.

In March 2021 Interserve rebranded its construction and engineering business as Tilbury Douglas.

An Interserve statement said: ‘”Interserve has worked extensively with the Information Commissioner’s Office (ICO) and the National Cyber Security Centre since first reporting the cyber incident in May 2020.

“Interserve strongly disputes that its staff and the company’s response were in any way complacent.

“Interserve took extensive steps to resolve the incident, engaging leading cyber response companies, and made significant investments across its operating companies to mitigate the potential impacts of the cyber incident on its past and present staff.

“It also sought to reduce the risk of future incidents and successfully facilitate the safe and effective ongoing operations of Tilbury Douglas and the facilities management business acquired by Mitie Group PLC.

“Interserve will continue to prioritise the interests of its past and present staff, counterparties and other stakeholders while engaging with the ICO to resolve their investigations”

Latest news

Costain margin heads for 4.5% after half-year profit rise

Roads and HS2 rephasing hit transport revenues but £5.6bn forward book to support growth
1 hour ago

Hinkley contractors face prosecution over rebar mesh fall

Bouygues and Laing O'Rourke face action brought by the Office for Nuclear Regulation
18 hours ago

Farrans to build new £59m Paisley bridge

Work to start soon on transport project for Renfrewshire Council
11 hours ago

Crown Estate hires Olympics village veteran to lead delivery push

John Nicholson to oversee £16bn portfolio’s major UK development pipeline.
42 minutes ago

Henry Boot gets green light for 2,500 new homes

Hallam Land division sees signs planning system is speeding-up
2 hours ago

Wates inks £100m deal on first new-design prison houseblocks

HMP Onley expansion leads roll-out of new standardised design
24 hours ago

£122m deal to unlock Newcastle’s last brownfield site

Land remediation funding paves way for 2,500-home Forth Yards neighbourhood
1 day ago

McLaren lands Heathrow logistics deal

1.6 hectare airport site to be transformed into modern warehouses
1 day ago

McAlpine veteran to lead T&T’s project management drive

Former Olympic Stadium lead Mike O’Donnell takes lead role with focus on major capital project delivery
1 day ago

IES snaps up Nexus Power out of administration

Utilities group strengthens expertise in 400kV jointing and offshore markets
1 day ago

Thames Water tenders £120m water main rehab deal

Company seeks 2–5 contractors for London and South East renewal works
1 day ago

Lower Thames Crossing to lead green planning reforms

New system to avoid another £100m HS2 bat tunnel
1 day ago

Mace lands latest 30-storey City of London tower

85 Gracechurch Street near Leadenhall Market to be transformed
2 days ago

Vinci gets go-ahead for £250m Stockport 8 scheme

Contractor to start first phase of 435 net zero homes next year
2 days ago

£80m bid race to convert Oxford Debenhams into labs

Crown Estate advance plan to convert former six storey department store
2 days ago

Bennett steps-in to finish Guinness Covent Garden brewery

Original fit-out contractor Beck Interiors fell into administration
2 days ago

Work-to-rule set to hit Sellafield clean-up

Action by 1,500 construction workers across 34 contractors
2 days ago

Aureos breaks ground on £45m Howden Relief Road

Yorkshire road will pave way for 2,000-home scheme
2 days ago

Oxford United win green light for £150m all-electric stadium

Planners back 16,000-seat Kidlington ground with hotel, plaza and community hub
5 days ago

Demolition record as eight cooling towers come down

Watch Brown & Mason set record at Cottam Power Station
6 days ago

Hitachi Energy named for EGL3 converter station deal

Firm to build major HVDC converter stations in Aberdeenshire and West Norfolk
5 days ago

PAS NW secures landmark £20m civils deal in Lancashire

Groundworks firm wins infrastructure for 429-home Wain Homes scheme
5 days ago

Subcontractors wanted for jobs across the South West

Register now for latest Constructionline event in Bristol
5 days ago

Profits double at Octavius as road and rail work grows

Recent acquisitions add to turnover growth at infrastructure specialist
6 days ago

Quarterly construction output growth masks orders slide

New orders down by over 8% driven by fall in infrastructure and offices
6 days ago

Vinci UK swings back into profit after group restructure

£166m cash injected to strengthen building and facilities operations balance sheets
7 days ago

Staged procurement to make comeback as pricing risk bites

Developers turn to staged deals to control costs on big-ticket commercial jobs
6 days ago

McGee profit halves as project start delays hit

Revenue up 24% but profits fall on higher carry costs
6 days ago

Vistry to deliver 2,300 homes at Rugeley power station site

139-acre brownfield site has already been extensively remediated
6 days ago

Andrew Scott wins role on Swansea’s next big office build

Contractor appointed for detailed design of 800-desk city centre hub.
6 days ago