grc-scanSecurity & governance
ICO watch · UK30 June 2026Archived edition

ICO fines & breach roundup

This edition was published on 30 June 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest roundup for the current picture.

The takeaway

Look across these and the story barely changes: the fines follow missing basics, not exotic attacks. No MFA, unpatched systems, poor access control, and weak supplier oversight come up again and again — and the ICO is now issuing fewer but far larger penalties aimed at systematic security failures. The encouraging flip-side: the controls that would have prevented most of these are cheap and well-defined. They're essentially the Cyber Essentials five — MFA, patching, secure configuration, access control and malware protection — plus knowing which suppliers hold your data and keeping your marketing consent clean. None of it requires a big budget; it requires doing the ordinary things on purpose.

ICO fines & breach roundup — 30 June 2026

A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.


1. South Staffordshire Water — nearly £1 million (May 2026)

The ICO fined South Staffordshire Plc and South Staffordshire Water close to £1 million following a major cyber attack and data breach that exposed customer personal data. It's one of the first big enforcement actions of 2026 and continues the regulator's focus on security failures rather than paperwork slips.

What your business should learn: The ICO is fining organisations for how they were breached — the security that wasn't in place — not just the fact a breach happened. Holding customer data (even just names, addresses and bank details for billing) puts you in scope. The defences they look for are the ordinary ones: patching, access control, and monitoring.


2. Capita — £14 million (October 2025), the ICO's largest fine

Capita was fined £14 million (reduced from an intended £45 million) after a cyber attack exposed the personal data of around 6.6 million people. The ICO found security shortcomings that let attackers move through Capita's systems.

What your business should learn: Capita is an outsourcer — it held data on behalf of other organisations. If you hand customer or staff data to a supplier (payroll, IT, a marketing agency), their breach is your problem too. Ask suppliers what security they have, and put it in the contract. Scale doesn't equal safety: a household-name processor still got the basics wrong.


3. Advanced Software — £3 million (March 2025), a LockBit ransomware victim

Advanced (a major NHS IT supplier) was fined £3 million after the 2022 LockBit ransomware attack that disrupted NHS 111 and care services. The ICO highlighted that the attackers got in through an account without multi-factor authentication (MFA).

What your business should learn: This is the single most repeated finding in ICO security cases — a remote-access account with no MFA. Turning on MFA for email, remote access and admin accounts is free or near-free, and it's the one control that would have stopped a string of these incidents.


4. DPP Law — £60,000 (April 2025), a law firm hit by ransomware

The ICO fined criminal-defence firm DPP Law £60,000 after a ransomware attack led to highly sensitive client information appearing on the dark web. The regulator found the firm hadn't acted on the basics of securing privileged accounts.

What your business should learn: Small professional-services firms — solicitors, accountants, recruiters — hold exactly the sensitive data attackers want, and the ICO does fine businesses this size. You don't need an enterprise budget; you need MFA, patching, and a tested backup.


5. Levales Solicitors — public reprimand (late 2024)

A smaller law firm, Levales, received a public reprimand (not a fine) after hackers accessed client details. The ICO pointed to no MFA and weak password management, and the firm couldn't even establish how the attackers got the credentials.

What your business should learn: Same lesson, smaller firm: MFA and decent passwords. Note the second point — they couldn't tell how they were breached. Basic logging and knowing who can access what isn't bureaucracy; it's how you contain an incident and show the ICO you took care.


6. The rules just got sharper — DUAA in force, PECR fines up to £17.5m

The Data (Use and Access) Act 2025 took effect on 5 February 2026. Among the changes: the cap on fines for electronic marketing breaches (PECR) — unsolicited emails, texts and calls — rose from £500,000 to £17.5 million, in line with UK GDPR. Separately, from June 2026 people generally have to complain to the organisation first before escalating to the ICO.

What your business should learn: If you do any marketing by email, text or phone, sloppy consent just got far more expensive. Make sure you have a lawful basis and a working unsubscribe, and keep records of consent. And because complaints now come to you first, having a simple, responsive way to handle a data request or complaint is worth setting up now.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Compiled from public ICO enforcement notices and UK data-protection news. For awareness only — not legal advice, and not affiliated with the ICO. Always check the ICO's own published notices for the authoritative detail.