University Fined £120,000 Over ‘Serious’ Security Breach

The Information Commissioner’s Office (ICO) has fined the University of Greenwich £120,000 following a “serious” security breach that exposed the personal details of nearly 20,000 people.

The ICO said it was the first time a university had been fined under the existing data protection rules, dating back to 1998.

The breach took place after a student and an academic created a microsite for a training conference in 2004.

Following the event’s conclusion, the site was neither closed down nor secured, and was compromised in 2013.


Systems breach

In 2016 multiple attackers exploited the vulnerable site to gain access to other parts of the university’s network. They gained access to the contact details of 19,500 people, including students, staff and alumni. That data included names, addresses and telephone numbers, the ICO said.

But 3,500 of the records also included more sensitive data on extenuating circumstances, details of learning difficulties and staff illness records. The information was posted online.

In one example, the breach disclosed the fact that a student had a brother who was fighting in a Middle Eastern army and references were made to an asylum application.

One of the students involved discovered the breach and reported it to the ICO and the BBC.

The microsite was developed without the university’s knowledge, but the ICO said it was nevertheless the university’s responsibility to take responsibility for security throughout the institution.

The ICO said it found the university didn’t have appropriate technical and organisational measures in place for ensuring security.

Overhaul

“Students and members of staff had a right to expect that their personal information would be held securely and this serious breach would have caused significant distress,” ICO head of enforcement Steve Eckersley said. “The nature of the data and the number of people affected have informed our decision to impose this level of fine.”

The University of Greenwich said it would not appeal and would take advantage of a prompt payment discount to reduce the fine by 20 percent to £96,000.

It said it had carried out an overhaul of data proctetion and security systems.

“No organisation can say it will be immune to unauthorised access in the future, but we can say with confidence to our students, staff, alumni and other stakeholders, that our systems are far more robust than they were two years ago as a result of the changes we have made,” said university secretary Peter Garrod.

Data protection agencies in Europe are to be given far greater powers to fine offenders under the General Data Protection Act (GDPR), which takes effect on 25 May.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Google, DOJ Closing Arguments Clash Over Search ‘Monopoly’

Google clashes with US Justice Department in closing arguments as government argues Google used illegal…

2 hours ago

Stanford AI Scientist Working On ‘Spatial Intelligence’ Start-Up

Prominent Stanford University AI scientist Fei-Fei Li reportedly completes funding round for start-up based on…

3 hours ago

Apple Shares Surge Ahead Of New AI Hardware Launches

Apple shares surge on optimism that new AI-focused hardware launches will drive renewed sales, starting…

4 hours ago

Biden Vetoes Republican Measure In Row Over Contractors’ Unions

Biden vetoes Republican-backed measure amidst dispute over 'joint employer' status for contract workers, affecting tech…

4 hours ago

Lawyers Say Strict Child Controls In China Show TikTok Could Do Better

Lawyers in US social media addiction action say strict controls on Douyin in China show…

5 hours ago

London Black Cabs Sue Uber In Latest Legal Tangle

More than 10,000 London black cab drivers sue Uber claiming company acted illegally to obtain…

5 hours ago