Technology Today

Image copyrightAFPThe Information Commissioner's Office (ICO) has fined Cathay Pacific Airways 500,000 for failing to protect customers' personal data.The UK watchdog said the airline's computer systems had exposed details of 111,578 UK residents and a further 9.4 million people from other countries.These included names, passport details, dates of birth, phone numbers, addresses and travel history."Appropriate security" was not in place between October 2014 and May 2018.The ICO said Cathay Pacific became aware of a problem in March 2018, when it suffered a "brute force" password-guessing attack.
The Hong Kong-based firm reported this to the ICO.
The regulator said it subsequently uncovered "a catalogue of errors" during a follow-up investigation, including:back-up files that were not password protectedinternet-facing servers without the latest patchesoperating systems that were no longer supported by the developerinadequate anti-virus protectionAt least one attack involved a server with a known vulnerability - but the fix was never applied, despite having been public knowledge for more than 10 years.
Steve Eckersley, the ICO's director of investigations, said there were "a number of basic security inadequacies across Cathay Pacific's system, which gave easy access to the hackers".The airline failed four out of five of the basic cyber-essentials guidance from the National Cyber Security Centre, he added.By Joe Tidy, Cyber-security reporterI'm told investigators were extremely concerned by the failures they found.
It paints a picture of a company that did not take security of personal data seriously, and today's fine will be a wake-up call to them and other firms.
It is, however, only a pittance compared to what it could have been if the hack had occurred more recently.
New GDPR rules have increased the potential maximum fine, and it's clear the failures here would have warranted a far more severe punishment.
Instead of a 500k penalty, Cathay Pacific could have been hit with a share-holder sickening 470m fine - 4% of its annual global turnover.
The 500,000 fine Cathay Pacific is facing is the maximum possible under the Data Protection Act 1998, which was used instead of the newer GDPR "due to the timing of the incidents in this investigation".In July 2019, the ICO announced it would fine British Airways 183m for a breach of its systems, and the Marriott hotel group 99.2m.
But both fines were delayed until later this year.The ICO said that Cathay Pacific had acted promptly once it became aware, and sought expert help from a top cyber-security firm, and had also contacted affected customers.The report also noted there were no confirmed cases of the personal data being misused - but that it was very likely it would be in future.In a statement about the fine, Cathay Pacific said it "would once again like to express its regret, and to sincerely apologise for this incident".It said "substantial amounts" of money had been spent on security in the past three years."However, we are aware that in today's world, as the sophistication of cyber-attackers continues to increase, we need to and will continue to invest in and evolve our IT security systems."





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Biggest ever UK landline switch off confirmed and your home could be on this list


Samsung will give shoppers up to £1000 if they ditch their old TV


Argos' surprise iPhone sale could encourage fans to update as £& pound; 200 is cut from rate


LG takes on Samsung with 50% television discount rate throughout uncommon sale


Worrying new WhatsApp warning issued and ignoring it could see you banned


Sky dishes Phone 16 at 'least expensive ever' cost and rare Apple offer is 'offering quickly'


'Apple AirTag and Samsung SmartTag drop in price - I don't go on a flight without one'


Amazon shoppers state these earphones more affordable than AirPods are 'the best' for physical fitness


Get £40 off Elgato stream deck that speeds up workflow in Amazon's surprise tech sale


Disregard streaming on Spotify, the cassette gamer returns and is way much better than before


Amazon reveals hi-tech robotics that could change big numbers of warehouse workers


All Android users placed on red alert - you must check your settings 'immediately'


Amazon Tech Week Sale: All details as Apple watches and Dyson fans drop in price


Free Amazon upgrade may convince you to ditch your Fire TV Stick for good


Last chance to get £150 off Samsung phone as rare discount ends in hours


Apple fans can pick up an iPhone 16 Pro for less in cost-splitting offer at Sky


Forget the Galaxy S25, Samsung confirms something 'light years ahead' is coming quickly


Broadband providers will pay you up to £300 to switch to a cheaper broadband deal


'I had a skydive at 14,000 feet, forgot one essential thing and the amazing took place'


Sky unveils major update to TV and broadband plan that Virgin and BT can't match


Going screen-free for a week urged by expert as they issue stark health warning


WhatsApp verifies immediate 24-hour due date - you could be obstructed from chats tonight


Amazon slashes price of Samsung Galaxy Watch to equal Samsung in flash offer


All PayPal account holders issued with immediate caution - do not disregard 10 brand-new rules


'I used a Chipolo card to track my luggage as a cheaper alternative to Apple AirTag'


Sky confirms immediate broadband alert - check your Wi-Fi or you may be at 'risk'


Top Tech: Samsung cuts £150 off Galaxy S25 Ultra and throws in free £219 earbuds


UK's 'worst' broadband validated - is your supplier top or bottom of the most recent list


SharkNinja recalls millions of pressure cookers after customers suffer third-degree burns


Amazon shoppers say £23 headphones are 'great value' in 82% price drop


Dyson cuts ₤ 80 off effective tower fan as UK reaches 26 degrees in heatwave


Worst online passwords verified - if yours is on this list you should change it now


Unique new Android phone arrives in UK this month and it's Nothing like its rivals


Your Virgin Media broadband may 'grind to a halt' today - don't make simple Wi-Fi error