Interserve hit with £4.4m fine after cyber attack

Grant Prior 3 years ago
Share

Interserve Group Ltd has been fined £4.4m by the Information Commissioner’s Office (ICO) for failing to keep personal information of its staff secure.

The fine follows a breach of data protection law in May 2020 when the company failed to put appropriate security measures in place to prevent the cyber attack, which enabled hackers to access the personal data of up to 113,000 employees through a phishing email.

The compromised data included personal information such as contact details, national insurance numbers, and bank account details.

The ICO said: “An Interserve employee forwarded a phishing email, which was not quarantined or blocked by the company’s system, to another employee who opened it and downloaded its content.

“This resulted in the installation of malware onto the employee’s workstation.

“The company’s anti-virus software quarantined the malware and sent an alert, but Interserve failed to thoroughly investigate the suspicious activity. If they had done so, Interserve would have found that the attacker still had access to the company’s systems.

“The attacker subsequently compromised 283 systems and 16 accounts, as well as uninstalling the company’s anti-virus solution. Personal data of up to 113,000 current and former employees was encrypted and rendered unavailable.

“The ICO investigation found that Interserve failed to follow-up on the original alert of a suspicious activity, used outdated software systems and protocols, and had a lack of adequate staff training and insufficient risk assessments, which ultimately left them vulnerable to a cyber attack.”

The ICO issued Interserve with a ‘notice of intent’ – a legal document that precedes a potential fine. The provisional fine amount was set at £4.4m. Having carefully considered representations from Interserve, no reductions were made to the final fine amount.

Interserve plc went into a pre-pack administration in March 2019 and was rebranded as Interserve Group. A break-up followed with Interserve’s facilities management business sold to Mitie in December 2020 and RMD Kwikform sold in October 2021 to Altrad.

In March 2021 Interserve rebranded its construction and engineering business as Tilbury Douglas.

An Interserve statement said: ‘”Interserve has worked extensively with the Information Commissioner’s Office (ICO) and the National Cyber Security Centre since first reporting the cyber incident in May 2020.

“Interserve strongly disputes that its staff and the company’s response were in any way complacent.

“Interserve took extensive steps to resolve the incident, engaging leading cyber response companies, and made significant investments across its operating companies to mitigate the potential impacts of the cyber incident on its past and present staff.

“It also sought to reduce the risk of future incidents and successfully facilitate the safe and effective ongoing operations of Tilbury Douglas and the facilities management business acquired by Mitie Group PLC.

“Interserve will continue to prioritise the interests of its past and present staff, counterparties and other stakeholders while engaging with the ICO to resolve their investigations”

Latest news

Green light for 1,600-home Oldham town centre overhaul

Plans for over 1,600 homes across six regeneration sites approved
43 minutes ago

Laing O’Rourke tops June contracts league

£919m animal super lab dominates new orders
7 minutes ago

DSM wins Norwich city centre clearance job

Anglia Square shopping centre clearance for £300m scheme
45 minutes ago

13-year-old becomes UK’s youngest qualified digger driver

Grandson of Gallagher Group chairman sets industry record
8 hours ago

Cubby reborn in £12m Svella-backed takeover

£50m revenue target set as 14 firms combine under new Cubby Group banner
23 hours ago

North East NHS trusts plot £3bn health estate overhaul

Market engagement begins for major construction push across four trusts
23 hours ago

HG goes green on cranes in £1.2m switch to battery power

Diesel-free crane drive cuts fuel bills by 94%
23 hours ago

Developer fined £165,000 for fire safety failings

Firm ignored fire safety orders on apartment job in Preston
23 hours ago

Bidding to start for £1.8bn North West framework

Contractors invited to bid for latest Procure Partnerships deal
24 hours ago

Hill hits record £90m profit as homes pipeline swells

Build-to-rent push and £4.8bn contracting book to fuel next growth phase
2 days ago

Rayner unveils £39bn plan to build 300,000 social homes

Council building revival and rent reform feature in social and affordable homes plan
2 days ago

Keltbray bounces back with £3.2m profit

Tighter controls and smarter project selection fuel strong turnaround
2 days ago

VINCI JV wins 500-home twin town centre revamps

Chester Northgate phase 2 and Northwich Weaver Square schemes move to delivery stage
2 days ago

80 energy projects unlocked as Ofgem backs grid expansion

£24bn energy networks deal gets green light from regulator
3 days ago

How to see your stories on the Enquirer

Join our Suppliers and Buyers directory to get your news published
2 days ago

Henley lands Midland Mill revamp on Leeds tower scheme

Restoration of 18th-century mill kicks off on South Bank regeneration project
2 days ago

New boss at Eric Wright Civil Engineering

Gavin Hulme takes top job as Diane Bourne moves to group role
2 days ago

Pinewood submits £1bn data centre plan

Studio giant adds green and learning spaces to tech hub blueprint
3 days ago

Record results after TClarke goes private

Britain's biggest M&E contractor flourishes after de-listing
3 days ago

Dalkia lands £200m nuclear maintenance deal

1,000 nuclear FM staff to join M&E contractor
3 days ago

Construction comeback to outpace wider economy

Arcadis forecast fueled by spending review optimism
4 days ago

First steel goes up on giant car battery site

Severfield gets to work on McAlpine Somerset site
4 days ago

Permasteelisa wins cladding deal on Bovis city tower

Facade specialist lands package at 60 Gracechurch Street
3 days ago

Fox buys recycled asphalt specialist Fisher

Acquisition adds major recycled asphalt capacity in north west
4 days ago

Major Building Safety Regulator shake-up to end tower delays

HSE stripped of control and top fire chiefs brought in to fast-track stalled schemes
4 days ago

Hinkley trio sign Sizewell civils deal

Balfour,Bouygues and Laing O'Rourke form Civil Works Alliance for new power station
4 days ago

£3.9bn data centre plan for Ravenscraig steelworks

Green energy to power massive new steel to silicon AI campus
4 days ago

Breakthrough on HS2’s second longest tunnel

8.4 mile Northolt to Old Oak Common drive completes
4 days ago

Neilcott on fast-track to debt-free employee ownership

£22.5m loan nearly paid down after big profit year
4 days ago

TfL kicks off race for £700m Tube station upgrade

South Kensington and Elephant & Castle top the pipeline list
4 days ago