Major UK Outsourcer Hit With Multi-Million Dollar Fine Due to a Phishing Attack

Stu Sjouwerman | Oct 24, 2022

UK Phishing AttackBritain's data watchdog has fined major construction group Interserve with a £4.4m fine. This was due to a cyber attack stole personal and financial details for over 113,000 employees and the company failed to stop the attack.

This phishing attack was very unique as it occurred over two years ago, and the company broke data protection law by not taking action to prevent the attack from occurring in the first place. The  Information Commissioner’s Office (ICO) claimed that the company had outdated systems and a lack of end user education that resulted into a successful phishing attack. 

In a statement by John Edwards, UK Information Commissioner,“Leaving the door open to cyber-attackers is never acceptable, especially when dealing with people’s most sensitive information. The biggest cyber-risk businesses face is not from hackers outside of their company but from complacency within their company.”

This incident should serve as a cautionary tale that one phishing email can cost your organization millions. New-school security awareness training can ensure your users have the proper training to spot and report any suspicious emails that come their way. 

The Guardian has the full story

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.