Technology Today

Image copyrightAFPThe Information Commissioner's Office (ICO) has fined Cathay Pacific Airways 500,000 for failing to protect customers' personal data.The UK watchdog said the airline's computer systems had exposed details of 111,578 UK residents and a further 9.4 million people from other countries.These included names, passport details, dates of birth, phone numbers, addresses and travel history."Appropriate security" was not in place between October 2014 and May 2018.The ICO said Cathay Pacific became aware of a problem in March 2018, when it suffered a "brute force" password-guessing attack.
The Hong Kong-based firm reported this to the ICO.
The regulator said it subsequently uncovered "a catalogue of errors" during a follow-up investigation, including:back-up files that were not password protectedinternet-facing servers without the latest patchesoperating systems that were no longer supported by the developerinadequate anti-virus protectionAt least one attack involved a server with a known vulnerability - but the fix was never applied, despite having been public knowledge for more than 10 years.
Steve Eckersley, the ICO's director of investigations, said there were "a number of basic security inadequacies across Cathay Pacific's system, which gave easy access to the hackers".The airline failed four out of five of the basic cyber-essentials guidance from the National Cyber Security Centre, he added.By Joe Tidy, Cyber-security reporterI'm told investigators were extremely concerned by the failures they found.
It paints a picture of a company that did not take security of personal data seriously, and today's fine will be a wake-up call to them and other firms.
It is, however, only a pittance compared to what it could have been if the hack had occurred more recently.
New GDPR rules have increased the potential maximum fine, and it's clear the failures here would have warranted a far more severe punishment.
Instead of a 500k penalty, Cathay Pacific could have been hit with a share-holder sickening 470m fine - 4% of its annual global turnover.
The 500,000 fine Cathay Pacific is facing is the maximum possible under the Data Protection Act 1998, which was used instead of the newer GDPR "due to the timing of the incidents in this investigation".In July 2019, the ICO announced it would fine British Airways 183m for a breach of its systems, and the Marriott hotel group 99.2m.
But both fines were delayed until later this year.The ICO said that Cathay Pacific had acted promptly once it became aware, and sought expert help from a top cyber-security firm, and had also contacted affected customers.The report also noted there were no confirmed cases of the personal data being misused - but that it was very likely it would be in future.In a statement about the fine, Cathay Pacific said it "would once again like to express its regret, and to sincerely apologise for this incident".It said "substantial amounts" of money had been spent on security in the past three years."However, we are aware that in today's world, as the sophistication of cyber-attackers continues to increase, we need to and will continue to invest in and evolve our IT security systems."





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Sky TV block as brand-new crackdown interrupts UK homes from viewing content totally free


Sky's biggest-ever conserving on Gigafast broadband cuts £& pound; 96 off the ultimate upgrade


Google is fixing a major issue with your Gmail inbox, and free upgrade is coming soon


Top Tech: 5 Amazon-rivalling deals from Apple, Samsung, Shark and more


Amazon Prime Day: Favourite tech gizmos and home appliances we actually use and love


Consumers can get an Echo Pop speaker for less than ₤ 6 if they do one easy thing


Sky is dispensing a huge upgrade, however just if your postcode is on this list


Amazon slashes ₤ 450 off Shark self-emptying robotic vacuum in mega Prime Day offer


Newest Kindle hits lowest ever cost in Amazon Prime Day deal with over ₤ 100 off


Samsung unveils new Galaxy, and it makes your current Android phone appearance extremely inferior


Simply hours remain on Virgin Media's complimentary 4K TV deal - act quickly


Everyone with an Android phone placed on red alert as massive new threat validated


The 'finest' smart device of 2025 confirmed - has the iPhone or Android come out on top


Amazon's best Apple deals for Prime Day consisting of iPhone, iPad and AirPods


Tech professional warns 'never state yes' to 3 questions from callers you don't recognise


Millions of Brits 'forced to function as online security guards' for elderly family members


Leading Tech: Virgin Media's totally free television giveaway ends quickly as 48-hour countdown begins


All Amazon Prime users put on high alert - you need to follow 4 new rules today


Amazon gives you 3 reasons to ditch your Fire TV Stick and try something new this week


Apple fans rush for 22% off AirPods Pro 2 as Amazon Prime Day kicks off


Paramount+ drops to £3.99 in half price sale ending this week


Amazon is handing out free Echo speakers this week and here's how to get yours


AI is the 'best organization partner' says youngest self-made female billionaire


Everyone using Amazon issued with an urgent 'don't click' warning this week


Sky is dishing out free TV channel upgrades, and here's how to watch it


Apple fans rushing for ₤ 35 iPhone 16 Pro Max as Sky uses payday deal


'I visited Chinese city which is like sci-fi movie with robots and noiseless trains'


Top Tech: Amazon's best early Prime Day deals including Ring, Tefal and Nespresso


Brits now 'obsessed' with health tracking and say it's key to motivation