grc-scanSecurity & governance
ICO watch · UK2 July 2026Archived edition

ICO fines & breach roundup

This edition was published on 2 July 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest roundup for the current picture.

The takeaway

None of the incidents in this roundup started with a sophisticated, unstoppable attack. A marketing firm ignored basic consent rules until the complaints piled up. A police force extracted more personal data than it needed and forwarded it without checking who should see it. A widely-used piece of supplier software had a known vulnerability that wasn't patched in time to stop it being exploited at scale. The common thread is that harm keeps coming from ordinary lapses in ordinary processes — the "did this person actually consent," "does this recipient need to see all of this," and "is this software patched" questions that get asked once, if at all, and then forgotten. None of those questions need a security budget to answer. Keep a consent record you actually check before sending marketing, get in the habit of trimming data down to what a recipient genuinely needs before you share it, and know which of your suppliers hold your customers' data and how seriously they take patching. Those three habits, kept up consistently, would have prevented every case above.

ICO fines & breach roundup — 2 July 2026

A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.


1. KRA Consultancy Ltd — £300,000 (June 2026), 5.5 million unlawful marketing texts

The ICO fined Manchester-based debt-solutions marketing firm KRA Consultancy Ltd £300,000, announced in late June 2026, and separately ordered it under an enforcement notice to stop its marketing activity. Between April 2022 and May 2025 the firm sent more than 5.5 million unsolicited marketing texts to people who had previously been declined for a loan — a breach of the Privacy and Electronic Communications Regulations (PECR), which require clear consent before you can market to someone electronically. The investigation, triggered by tens of thousands of public complaints, also found the firm had sent fake "bailiff" texts falsely warning recipients that an enforcement agent would visit within 48 hours to seize their belongings, and had asked an overseas telecoms provider whether the messages could be made "completely untraceable."

What your business should learn: If you send any marketing by text, email or phone, PECR applies to you regardless of your size — "we bought a list" or "they gave us their number once for something else" is not consent. Keep a simple record of when and how each contact opted in, make opting out a one-tap action, and never send anything designed to alarm or pressure someone into responding. The scale here is extreme, but the same consent rules apply just as strictly to a five-person business sending its first marketing email.


2. Police Scotland — £66,000 fine and reprimand, a journalist's phone data mishandled

Earlier in 2026 the ICO fined Police Scotland £66,000 and issued a formal reprimand after officers extracted the entire contents of a crime reporter's mobile phone during an investigation, without filtering out material unconnected to the case, then shared the unredacted extraction — including sensitive personal data — in a disclosure bundle with a third party who had no need to see it. This one is a little older than the rest of this roundup, but the failure pattern is distinct enough to be worth including on its own: it wasn't a hack or an outside attacker, it was over-collection and a missing "does this person actually need to see all of this?" check before the data went out the door.

What your business should learn: Before you extract, export or forward a chunk of personal data — customer records, an ex-employee's device, an old shared inbox — stop and ask what the recipient genuinely needs, and strip out the rest. A short, boring checklist ("am I sending the whole thing, or just the relevant part?") applied before you hit send costs nothing and would have stopped this case outright.


3. University of Nottingham — breach affecting 450,000+ people; no ICO penalty issued yet (June 2026)

In June 2026 the University of Nottingham confirmed a data breach after the ShinyHunters hacking group exploited a vulnerability in Oracle's PeopleSoft platform — the third-party software the university relied on to manage student records — as part of a wider campaign reported to have hit over 100 organisations worldwide. The exposed data reportedly includes names, addresses, phone numbers and passport numbers for around 454,600 current and former students and alumni. As of this roundup, the ICO has not published a fine, reprimand or enforcement notice against the university — this is included as a notable breach still under investigation, not a confirmed enforcement outcome, and any penalty figure would be speculation at this point.

What your business should learn: This breach didn't start with the university's own mistake — it started with a vulnerability in software a supplier built. If you rely on third-party platforms to hold or process personal data (booking systems, CRMs, HR software, payment processors), ask them directly how quickly they patch known vulnerabilities and how they'd tell you if something went wrong. Your data's safety depends on your suppliers' update discipline as much as your own — so it belongs in the contract, not just assumed.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Compiled from public ICO enforcement notices and UK data-protection news. For awareness only — not legal advice, and not affiliated with the ICO. Always check the ICO's own published notices for the authoritative detail.