Interserve hit with £4.4m fine after cyber attack

Grant Prior 2 years ago
Share

Interserve Group Ltd has been fined £4.4m by the Information Commissioner’s Office (ICO) for failing to keep personal information of its staff secure.

The fine follows a breach of data protection law in May 2020 when the company failed to put appropriate security measures in place to prevent the cyber attack, which enabled hackers to access the personal data of up to 113,000 employees through a phishing email.

The compromised data included personal information such as contact details, national insurance numbers, and bank account details.

The ICO said: “An Interserve employee forwarded a phishing email, which was not quarantined or blocked by the company’s system, to another employee who opened it and downloaded its content.

“This resulted in the installation of malware onto the employee’s workstation.

“The company’s anti-virus software quarantined the malware and sent an alert, but Interserve failed to thoroughly investigate the suspicious activity. If they had done so, Interserve would have found that the attacker still had access to the company’s systems.

“The attacker subsequently compromised 283 systems and 16 accounts, as well as uninstalling the company’s anti-virus solution. Personal data of up to 113,000 current and former employees was encrypted and rendered unavailable.

“The ICO investigation found that Interserve failed to follow-up on the original alert of a suspicious activity, used outdated software systems and protocols, and had a lack of adequate staff training and insufficient risk assessments, which ultimately left them vulnerable to a cyber attack.”

The ICO issued Interserve with a ‘notice of intent’ – a legal document that precedes a potential fine. The provisional fine amount was set at £4.4m. Having carefully considered representations from Interserve, no reductions were made to the final fine amount.

Interserve plc went into a pre-pack administration in March 2019 and was rebranded as Interserve Group. A break-up followed with Interserve’s facilities management business sold to Mitie in December 2020 and RMD Kwikform sold in October 2021 to Altrad.

In March 2021 Interserve rebranded its construction and engineering business as Tilbury Douglas.

An Interserve statement said: ‘”Interserve has worked extensively with the Information Commissioner’s Office (ICO) and the National Cyber Security Centre since first reporting the cyber incident in May 2020.

“Interserve strongly disputes that its staff and the company’s response were in any way complacent.

“Interserve took extensive steps to resolve the incident, engaging leading cyber response companies, and made significant investments across its operating companies to mitigate the potential impacts of the cyber incident on its past and present staff.

“It also sought to reduce the risk of future incidents and successfully facilitate the safe and effective ongoing operations of Tilbury Douglas and the facilities management business acquired by Mitie Group PLC.

“Interserve will continue to prioritise the interests of its past and present staff, counterparties and other stakeholders while engaging with the ICO to resolve their investigations”

Latest news

Carpenter killed by falling timber frame panels

Court fines specialist contractor £8,000 after site tragedy
9 hours ago

Road sweeper specialist files administration notice

Go Plant lodges court notice
15 hours ago

Anglian Homes rides in to finish crashed Everest contracts

Rival doubled glazed window specialist commits to complete orders
14 hours ago

Final work starts to connect super sewer to London system

End in sight with 1.5m thick concrete wall to be demolished to link-up to Lee Tunnel sewer system
15 hours ago

Legal challenge launched against £1.5bn A66 dualling

Balfour Beatty, Kier and Keltbray must now await outcome of court challenge
15 hours ago

John F Hunt wins 24-storey Battersea tower

Specialist to carry-out demolition, enabling works and RC frame construction
1 day ago

William Hare wins steelwork on £500m Broadgate towers

Specialist to work on 2 Finsbury Avenue with McAlpine
1 day ago

McAlpine appoints MD to grow ventures business

Owain Thomas will build on private rental and healthcare development successes
1 day ago

BAM Co-op Live Arena opening delayed yet again

Another gig cancelled last night amid last minute safety concerns
2 days ago

National Grid unveils winners for £9bn network upgrade

New 'enterprise model' to deliver infrastructure schemes quicker and cheaper
2 days ago

Turkish insulation panel maker to build £45m UK factory

Assan Panel to open first UK plant at Freeport East
2 days ago

Expanding consultant Stantec swoops for Hydrock

Stantec UK business expands by a third as 950 staff join from Bristol-based engineer
2 days ago

Contractors wanted for £800m highways deal

Bids invited for Eastern Highways Alliance Framework 4
2 days ago

Galliford Try names group head of infrastructure

David Lowery promoted to Divisional Managing Director – Infrastructure.
2 days ago

Chigwell Group looks at stock market listing

Essex contractor registers as Public Limited Company
3 days ago

A57 Mottram Bypass clears final legal challenge

Balfour Beatty to get go-ahead to start shortly
3 days ago

100 jobs axed as Geoffrey Osborne confirms administration

Chairman Andrew Osborne calls it a 'sad day' as board loses fight for survival
3 days ago

Midgard set for Notting Hill office tower overhaul

Landmark project edges towards final approval after 10-year planning saga
3 days ago

Cumbrian civils firm clinches £40m Sellafield contract

Civils specialist Stobbarts will support McAlpine on groundworks and concrete
3 days ago

Designers named for London 2000-bed student rooms job

Bouygues will build £400m London School of Economics student scheme next to Tate Modern
3 days ago

£117m-turnover contractor files administration notice

ARJ Construction lodges court notice
4 days ago

£1bn London Blackfriars tower blocks approved

Trio of buildings rising to 45, 40 and 22 storeys approved by Southwark Council
4 days ago

Council decides to end Balfour deal after 13 years

Contractor has been maintaining roads across Herefordshire since 2013
4 days ago

Six civils clients to switch to low carbon concrete and steel

National Highways, Northumbrian Water and Sellafield sign fresh decarbonising pledge
4 days ago

Fortem extends homes repair deal across Birmingham

Willmott Dixon owned firm adds another two years to deal worth £170m
4 days ago

Kier wins £118m civil service Darlington hub

Work is expected to start towards the end of this year
4 days ago

Green light for 34-storey Digbeth apartments tower

480 flats will be delivered for Clarion housing association
4 days ago

LHC starts race for major retrofit and decarb framework

Hunt starts for firms to help with 6.1m social homes upgrade target
5 days ago

Windows giant Everest crashes into administration

Around 350 jobs at risk while hunt starts for a buyer to salvage business
5 days ago

Green light for £500m Newcastle health complex

Mixed use scheme will promote healthy living across all stages of life
5 days ago

Contractor services