Interserve hit with £4.4m fine after cyber attack

Grant Prior 3 years ago
Share

Interserve Group Ltd has been fined £4.4m by the Information Commissioner’s Office (ICO) for failing to keep personal information of its staff secure.

The fine follows a breach of data protection law in May 2020 when the company failed to put appropriate security measures in place to prevent the cyber attack, which enabled hackers to access the personal data of up to 113,000 employees through a phishing email.

The compromised data included personal information such as contact details, national insurance numbers, and bank account details.

The ICO said: “An Interserve employee forwarded a phishing email, which was not quarantined or blocked by the company’s system, to another employee who opened it and downloaded its content.

“This resulted in the installation of malware onto the employee’s workstation.

“The company’s anti-virus software quarantined the malware and sent an alert, but Interserve failed to thoroughly investigate the suspicious activity. If they had done so, Interserve would have found that the attacker still had access to the company’s systems.

“The attacker subsequently compromised 283 systems and 16 accounts, as well as uninstalling the company’s anti-virus solution. Personal data of up to 113,000 current and former employees was encrypted and rendered unavailable.

“The ICO investigation found that Interserve failed to follow-up on the original alert of a suspicious activity, used outdated software systems and protocols, and had a lack of adequate staff training and insufficient risk assessments, which ultimately left them vulnerable to a cyber attack.”

The ICO issued Interserve with a ‘notice of intent’ – a legal document that precedes a potential fine. The provisional fine amount was set at £4.4m. Having carefully considered representations from Interserve, no reductions were made to the final fine amount.

Interserve plc went into a pre-pack administration in March 2019 and was rebranded as Interserve Group. A break-up followed with Interserve’s facilities management business sold to Mitie in December 2020 and RMD Kwikform sold in October 2021 to Altrad.

In March 2021 Interserve rebranded its construction and engineering business as Tilbury Douglas.

An Interserve statement said: ‘”Interserve has worked extensively with the Information Commissioner’s Office (ICO) and the National Cyber Security Centre since first reporting the cyber incident in May 2020.

“Interserve strongly disputes that its staff and the company’s response were in any way complacent.

“Interserve took extensive steps to resolve the incident, engaging leading cyber response companies, and made significant investments across its operating companies to mitigate the potential impacts of the cyber incident on its past and present staff.

“It also sought to reduce the risk of future incidents and successfully facilitate the safe and effective ongoing operations of Tilbury Douglas and the facilities management business acquired by Mitie Group PLC.

“Interserve will continue to prioritise the interests of its past and present staff, counterparties and other stakeholders while engaging with the ICO to resolve their investigations”

Latest news

Three arrested in Blu-3 and Mace bribery probe

Serious fraud office swoops over alleged £3m bribes to former Mace associates
2 hours ago

Scotland’s most complex A9 dualling job heads to market

Market testing starts for £205m Pitlochry to Killiecrankie 6.4km upgrade
38 minutes ago

Turkish contractor Limak to build new Luton Town stadium

Construction to start this summer on 25,000-seater venue
10 hours ago

Murphy on board at new £32m rail station

Construction to start next year at Golborne station
9 hours ago

HS2 engineers finish UK’s heaviest bridge slide early

A46 Kenilworth Bypass reopens 30 hours earlier than planned
8 hours ago

Bowmer + Kirkland to build £190m Oxford science scheme

Work to start at end of next month on 180,000 sq ft Fabrica scheme
16 hours ago

New BAM leisure centre pool springs a leak

Contractor investigating "technical issues" delaying new £36m green leisure centre
1 day ago

United Living lands £250m HyNet pipeline deal

Firm wins deal to design and build over 34km of pipework to collect CO2
16 hours ago

Hydrogen diggers get green light to use roads

JCB hails historic decision for advance of hydrogen-fuelled plant on sites
17 hours ago

Go-ahead for McAleer & Rushe Glasgow student job

£100m funding deal paves way for 591-bed student tower
17 hours ago

Fly-tippers to get their vehicles crushed

Drones will be used to identify cowboy construction waste operators
17 hours ago

Green light for £150m West End office revamp

Shaftesbury Avenue office retrofit retains 75% of original building
2 days ago

Morgan Sindall lands £20m Brunswick Wharf scheme in Bideford

North Devon waterside project will provide 100 flats
1 day ago

Former Keltbray managers jailed after corruption trial

Jail sentences following bribery probe on jobs including Battersea Power Station
2 days ago

Lidl pumps £500m into store and logistics expansion

Discounter plans 40 new stores this year as expansion ramps up
2 days ago

JJ Rhatigan UK profit jumps as turnover tops £150m

Irish contractor's expansion in England gathers pace
2 days ago

Driverless digger to be used on Taylor Woodrow site

Autonomous excavator to work at Manchester Airport after successful trial
2 days ago

MCS Build lands Basingstoke warehouse scheme

Construction starts this month after £26m funding deal
2 days ago

Leeds United unveil stadium revamp design

Club has still to set a timeframe for staged Elland Road upgrade
2 days ago

Bowmer & Kirkland boosts margins as profits surge to £69m

Revenue nudges up towards £1.3bn in year of expansion
3 days ago

Offshore construction starts on £4bn windfarm

Foundations for first of 95 turbines installed: Watch video
3 days ago

AECOM buys civils consultant Allen Gordon

Global giant acquires Scottish water and energy specialist
3 days ago

Plans in for £1bn Northern Gateway site in Manchester

Plan for 500-acre manufacturing and logistic park advance
3 days ago

RED wins £31m London Shoreditch student digs job

Two extra floors will be added to Willen House scheme
3 days ago

Deconstruct handed £12m Grenfell demolition

Firm maintaining building awarded job without bid race to speed process
3 days ago

Sizewell site workers get made to measure PPE

Bespoke fitting service on offer at new Bryson branch
3 days ago

Comment: Gateway is acting like a barricade

Contractors left banging their heads on an (unbuilt) brick wall
6 days ago

Final phase of £1.5bn Elephant and Castle revamp hits planning

Get Living submits revised plan for 500 homes and 450-bed student block
7 days ago

Ealing backs final phase of £1.3bn estate rebuild

Friary Park estate rebuild in Acton reaches end stage
6 days ago

Green light for scaled-down Nottingham student tower

Glasshouse Street scheme will deliver 247 student rooms
6 days ago

Contractor services