Interserve hit with £4.4m fine after cyber attack

Grant Prior 2 years ago
Share

Interserve Group Ltd has been fined £4.4m by the Information Commissioner’s Office (ICO) for failing to keep personal information of its staff secure.

The fine follows a breach of data protection law in May 2020 when the company failed to put appropriate security measures in place to prevent the cyber attack, which enabled hackers to access the personal data of up to 113,000 employees through a phishing email.

The compromised data included personal information such as contact details, national insurance numbers, and bank account details.

The ICO said: “An Interserve employee forwarded a phishing email, which was not quarantined or blocked by the company’s system, to another employee who opened it and downloaded its content.

“This resulted in the installation of malware onto the employee’s workstation.

“The company’s anti-virus software quarantined the malware and sent an alert, but Interserve failed to thoroughly investigate the suspicious activity. If they had done so, Interserve would have found that the attacker still had access to the company’s systems.

“The attacker subsequently compromised 283 systems and 16 accounts, as well as uninstalling the company’s anti-virus solution. Personal data of up to 113,000 current and former employees was encrypted and rendered unavailable.

“The ICO investigation found that Interserve failed to follow-up on the original alert of a suspicious activity, used outdated software systems and protocols, and had a lack of adequate staff training and insufficient risk assessments, which ultimately left them vulnerable to a cyber attack.”

The ICO issued Interserve with a ‘notice of intent’ – a legal document that precedes a potential fine. The provisional fine amount was set at £4.4m. Having carefully considered representations from Interserve, no reductions were made to the final fine amount.

Interserve plc went into a pre-pack administration in March 2019 and was rebranded as Interserve Group. A break-up followed with Interserve’s facilities management business sold to Mitie in December 2020 and RMD Kwikform sold in October 2021 to Altrad.

In March 2021 Interserve rebranded its construction and engineering business as Tilbury Douglas.

An Interserve statement said: ‘”Interserve has worked extensively with the Information Commissioner’s Office (ICO) and the National Cyber Security Centre since first reporting the cyber incident in May 2020.

“Interserve strongly disputes that its staff and the company’s response were in any way complacent.

“Interserve took extensive steps to resolve the incident, engaging leading cyber response companies, and made significant investments across its operating companies to mitigate the potential impacts of the cyber incident on its past and present staff.

“It also sought to reduce the risk of future incidents and successfully facilitate the safe and effective ongoing operations of Tilbury Douglas and the facilities management business acquired by Mitie Group PLC.

“Interserve will continue to prioritise the interests of its past and present staff, counterparties and other stakeholders while engaging with the ICO to resolve their investigations”

Latest news

Construction boss jailed for siphoning off cash for casino

Money removed from contracting firms before they went under
6 hours ago

Watkin Jones wins over £50m student digs campus upgrade

Work to start next month on phase 714-bed south London campus
10 hours ago

Severfield warns on profits blaming major project delays

Steelwork firm cancels share buyback and steps up cost cutting programme
14 hours ago

Administrators go in at aggregates firm Ashville

Administrators from Leonard Curtis now in charge of London based aggregates specialist
1 day ago

Costain start date for £67m Romford flyover replacement

Work to start this summer on Gallows Corner bridge rebuild
14 hours ago

North West regional civils contractor in administration

Colin Briscoe Construction employed 25 staff
13 hours ago

Technip wins old tyres to jet fuel recycling plant

£100m Sunderland plant will produce around 30,000t of liquid fuel
13 hours ago

Kier targets £400m of logistics work with Investec JV

Hemel Hempstead site marks start of new venture
14 hours ago

Watchdog MPs raise alarm over HS2 Euston station plan

Public spending watchdog red flags 'no plan or timescale' for London Terminus
4 days ago

Network Rail fined £3.41m after Surbiton track worker death

30-year-old track worker Tyler Byrne was struck by a passenger train in Surbiton
4 days ago

Government picks 43 consultants for Net Zero programmes

Jacobs, Mace, Mott MacDonald and Costain feature across multiple lots
4 days ago

£2.2bn Gatwick second runway decision delayed

Government 'minded to approve' expansion but puts back decision to October
4 days ago

Avant Homes gets green light for £68m Scottish site

Construction set to start in July
4 days ago

Funding deal for £237m Tide Construction student tower

48-storey project will be first major student scheme on Canary Wharf
4 days ago

McLaren wins £29m south east London industrial job

Crayford urban logistics hub starts construction
5 days ago

Government to license principal contractors after Grenfell

Seven firms criticised in Inquiry to face ban from government contracts
5 days ago

Taylor Wimpey fire safey retrofit costs rise by £88m

Cost inflation pushes up expected remediation costs
5 days ago

Green light for £100m A47 road junction upgrade

Long-awaited A47/A11 Thickthorn junction will support over 40,000 homes
5 days ago

Sisk starts remediation work for 1,600-home Birkenhead scheme

Wirral council has secured £52m for Hind Street Urban Village infrastructure
5 days ago

CITB set to spend £2m with advertising agency

Training body goes out to tender for media planning and buying contract
5 days ago

Plans unveiled for 50-storey plus Liverpool tower

Planning submission later this year for £1bn King Edward project
5 days ago

Overbury profits lift Morgan Sindall to another record year

Construction margin hits 3% as group daily cash soars to £374m
6 days ago

Galliford Try wins £45m high security prison fire safety retrofit

HMP Wakefield provides upgrade challenges in secure environments
6 days ago

Over 120 firms win £660m retrofit and decarb framework

LHC national framework covers capabilities from consultancy to retrofit works
6 days ago

Costain signs PM and engineering resources deal for Sizewell C

10-year framework will cover project managers and engineers, cost controllers and risk managers
6 days ago

Lovell Partnerships to build 2,260 South Wales homes

Cardiff and Vale of Glamorgan councils partnership to deliver homes over 10 years
6 days ago

HS2 Euston tunnel work put on hold

Supply chain told of delays in shock announcement
7 days ago

Gateway 2 approval delay pushes back Bristol student scheme

Student developer warns fire design approvals will push projects back 6 months
7 days ago

Axa submits plan for 46-storey London city tower

176m office block plan submitted after 22 Bishopsgate space fully let
7 days ago

Winners named for NHS building safety and fire compliance deal

66 specialists and consultants lined up to deliver compliance backlog
7 days ago

Contractor services