ICO fines & breach roundup — 22 July 2026
A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.
1. Craneware plc — Edinburgh healthtech firm discloses a cyberattack and data theft (20 July 2026)
Craneware plc, an Edinburgh-headquartered software company that supplies financial and billing software to roughly 2,000 US hospitals and thousands of clinics and pharmacies, disclosed on 20 July 2026 that it had suffered a cybersecurity incident resulting in unauthorised access to part of its data environment. The company says a "significant volume" of file names were viewed and exfiltrated — much of it non-sensitive or already-public regulatory data — but a subset of employee records and customer/partner data was also accessed and taken. Craneware says the intrusion has been contained, with no disruption to customer-facing services, and it has notified UK and US authorities, including the ICO and the FBI, and brought in external forensic specialists. At the time of writing the company has not attributed the attack to a specific group or method, so treat the "ransomware" label some outlets are using as unconfirmed.
What your business should learn: Craneware did several things right that are worth copying exactly: it activated an incident-response process immediately, brought in outside forensic help rather than trying to assess the damage alone, notified the regulator without waiting to know the full scope, and was public and specific about what it did and didn't yet know. You don't need a large IR retainer to copy that playbook — write down now, before an incident, who you'd call first (a local IT/security contact, your insurer if you hold cyber cover, and the ICO if personal data might be involved) and what you'd tell customers in the first 24 hours. Deciding that under pressure, mid-breach, is how bad disclosures happen.
2. Two Scattered Spider hackers jailed for 5.5 years over the £29m Transport for London hack (16 July 2026)
Thalha Jubair, 20, and Owen Flowers, 18 — both linked to the cybercrime collective "Scattered Spider" — were each sentenced to five years and six months at Woolwich Crown Court, in what the National Crime Agency has called the UK's biggest cybercrime case to date. Between 31 August and 3 September 2024 the pair hacked into Transport for London's Microsoft identity system, taking 148 systems offline (some for weeks) and forcing all 27,000 TfL staff into the office for in-person password resets. According to the Crown Prosecution Service and National Crime Agency, the attack cost TfL an estimated £29 million to remediate. The method matches Scattered Spider's well-documented playbook: social engineering an IT help desk — calling and impersonating a legitimate employee — to get credentials reset and multi-factor authentication bypassed, rather than exploiting any software flaw. Both pleaded guilty on the day their trial was due to start; Jubair was separately caught in part because of a cryptocurrency wallet trail. Scattered Spider (or closely affiliated groups) has also been tied to the 2025 cyberattacks on Marks & Spencer and the Co-op, and — with less certainty — Jaguar Land Rover.
What your business should learn: The single most exploitable weak point in this whole campaign wasn't a firewall or a server — it was a phone call to a help desk. If your business (or your outsourced IT provider) can reset a password or an MFA device on request, write down a verification step that doesn't rely on the caller simply sounding legitimate: a callback to a number already on file, a manager sign-off, or a pre-agreed security question that isn't guessable from LinkedIn. It costs nothing and it is exactly the control that would have stopped this specific attack. Separately, treat this as a data point on real-world consequences: cyber-extortion crews are being caught and jailed for years, but only after tens of millions of pounds of damage was already done — prevention is still far cheaper than either the ransom or the recovery bill.
3. The ICO's 2025/26 annual report: £33.8 million in fines, and the pattern behind them (published July 2026)
The regulator's Annual Report and Accounts for 2025/26 (published to Parliament as HC 531) shows it issued £33.8 million in data-protection fines over the year — a marked jump on prior years, driven by a small number of very large penalties rather than many small ones. The single biggest was the £14.47 million fine against Reddit for children's-privacy failures; the regulator also opened or progressed investigations into major platforms including X and TikTok. Underneath the headline tech fines, the ICO's day-to-day enforcement workload — as this series has tracked case by case over recent weeks — continues to be dominated by two much more mundane, much more avoidable categories: unlawful marketing under PECR (nuisance calls and spam texts, several hundred thousand pounds at a time) and basic security failures following a cyberattack (weak access controls, missing MFA, slow breach response). Those are the cases an ordinary SME is actually at risk of, not a nine-figure children's-privacy investigation.
What your business should learn: Don't read "£33.8 million" and conclude ICO enforcement is only a big-company problem — it's the opposite lesson. The eye-catching fines are for large platforms; the volume of enforcement action, case after case in this series, is Manchester debt-marketing firms, home-improvement callers, small law firms and local service companies, fined for exactly the same two failures every time: marketing without proper consent, and treating basic account security (MFA, access reviews, prompt patching) as optional. Both are inexpensive to fix compared with a five- or six-figure fine, and both are things a non-technical owner can personally check this month without hiring a consultant.
Sources
- Investegate — Craneware plc: Notice of Cyber Security Incident
- IT Pro — Health tech firm Craneware admits "significant volume" of customer and employee data exposed in cyber attack
- SC Media — Craneware confirms customer and employee data exposed in security incident
- National Crime Agency — Two sentenced for hacking Transport for London in UK's biggest ever cyber crime case
- Crown Prosecution Service — Cyberhackers who targeted TfL jailed for more than five years each
- The Record — Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack
- The Hacker News — Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
- UK Government — Information Commission Annual Report and Accounts 2025/26 (HC 531)
- MLex — UK regulator issued nearly £34m in data protection fines in 2025-2026, report says
- ICO — Reddit issued with £14.47m fine for children's privacy failures