Data Stolen From Previous Employer.
Discussion
Looking for a bit of advice, not sure if this is the right forum.
Just received a letter from a previous employer advising that they have been a victim of a cyber attack, and they have advised:
We have conducted a review of the files in question, and our investigations have shown that personal data of the following type relevant to your employment may include:
Name, DOB, Gender, Current and Former Address, Home and Mobile Number, Financial Information, NI Number, Salary Details, Pension Contributions, Medical Information, CV, Contract of Employment, Disciplinary/Absence Records.
They have given me a 12 month subscription to Transunion International UK Limited, and just suggested things to make sure that im not having finance or anything taken out in my name.
Just wondering if there is something more I should be doing? or if there is more that they should be doing?
Just received a letter from a previous employer advising that they have been a victim of a cyber attack, and they have advised:
We have conducted a review of the files in question, and our investigations have shown that personal data of the following type relevant to your employment may include:
Name, DOB, Gender, Current and Former Address, Home and Mobile Number, Financial Information, NI Number, Salary Details, Pension Contributions, Medical Information, CV, Contract of Employment, Disciplinary/Absence Records.
They have given me a 12 month subscription to Transunion International UK Limited, and just suggested things to make sure that im not having finance or anything taken out in my name.
Just wondering if there is something more I should be doing? or if there is more that they should be doing?
Has the company notified the ICO within 72 hours, as required for this sort of breach?
https://ico.org.uk/for-organisations/report-a-brea...
https://ico.org.uk/for-organisations/report-a-brea...
EmailAddress said:
Why was any of that info not air gapped and encrypted.
- Because it's not the launch codes.
- Because in order to be usable ordinary business reasons, it can't be airgapped.
I'm trying to imagine an HR person having to go through a persontrap into a faraday cage in a building with HGV and blastproof walls and armed guards just to get someone's national insurance number so they can process a P60 form.
Chromegrill said:
Has the company notified the ICO within 72 hours, as required for this sort of breach?
https://ico.org.uk/for-organisations/report-a-brea...
There is no mention of whether they have reported it in the letter, is this something I should do?https://ico.org.uk/for-organisations/report-a-brea...
Smurfsarepeopletoo said:
Chromegrill said:
Has the company notified the ICO within 72 hours, as required for this sort of breach?
https://ico.org.uk/for-organisations/report-a-brea...
There is no mention of whether they have reported it in the letter, is this something I should do?https://ico.org.uk/for-organisations/report-a-brea...
I would set expectations for ICO doing something to low.
My primary concern would be protecting myself, my credit history, etc. Did the company have any passwords that you have re-used anywhere else? If so I would change these as a priority.
Smurfsarepeopletoo said:
Chromegrill said:
Has the company notified the ICO within 72 hours, as required for this sort of breach?
https://ico.org.uk/for-organisations/report-a-brea...
There is no mention of whether they have reported it in the letter, is this something I should do?https://ico.org.uk/for-organisations/report-a-brea...
My view would be to ask for 3 years subscription and monitor your credit score.
I had similar a year or so back, from a huge global I used to work for. Infuriatingly, it seems that they transferred all of my PII out to a 3P payroll company AFTER I left.
There's some sort of class action underway as a result of this, although unlikely to deliver any big payouts, I'm told. I've never claimed compo from anyone for anything before, but due to the way I was treated by them when I worked there, and their sheer ineptitude in their actions, and the fact that they have completely ignored requests from me for further information, I've added my name to the list. They were a f
king awful company to work for (which is why I left).
I've already had two attempts to use my information fraudulently since it happened, fortunately both blocked by the providers.
There's some sort of class action underway as a result of this, although unlikely to deliver any big payouts, I'm told. I've never claimed compo from anyone for anything before, but due to the way I was treated by them when I worked there, and their sheer ineptitude in their actions, and the fact that they have completely ignored requests from me for further information, I've added my name to the list. They were a f
king awful company to work for (which is why I left).I've already had two attempts to use my information fraudulently since it happened, fortunately both blocked by the providers.
bobtail4x4 said:
I have to ask why they are still keeping your details?
they no longer have any connection to you,
Because there are certain statutes that have mandatory retention periods and the ICO’s own guidance suggests six years in line with the limitation act. You can of course under GDPR ask for your information to be removed if there is no longer a need to process it. Be careful when doing that though as when you may need a reference or tax information etc the response might not be what you expect they no longer have any connection to you,
CraigyMc said:
EmailAddress said:
Why was any of that info not air gapped and encrypted.
- Because it's not the launch codes.
- Because in order to be usable ordinary business reasons, it can't be airgapped.
I'm trying to imagine an HR person having to go through a persontrap into a faraday cage in a building with HGV and blastproof walls and armed guards just to get someone's national insurance number so they can process a P60 form.

Air gapped


EmailAddress said:
BrettMRC said:
CraigyMc said:
EmailAddress said:
Why was any of that info not air gapped and encrypted.
- Because it's not the launch codes.
- Because in order to be usable ordinary business reasons, it can't be airgapped.
I'm trying to imagine an HR person having to go through a persontrap into a faraday cage in a building with HGV and blastproof walls and armed guards just to get someone's national insurance number so they can process a P60 form.

Air gapped


Unless Catherine Zeta Jones lycra'd herself into the OP's offices overnight and started pulling harddrives, the info should simply not be available for an outside entity to exploit.
It's sloppy processes.
A breach of corporate data (work, projects etc) held in shared servers is somewhat difficult to mitigate against.
But the kind of info stated should not be.
From your comments, you do not.
Gassing Station | Speed, Plod & the Law | Top of Page | What's New | My Stuff


