grc-scanSecurity & governance
ICO watch · UK6 July 2026Archived edition

ICO fines & breach roundup

This edition was published on 6 July 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest roundup for the current picture.

The takeaway

Look past the different subject matter — ransomware, cold-calling, children's data — and the same failure shows up each time: an unglamorous, genuinely cheap check got skipped, and the absence of it is what turned an ordinary event into a serious one. Nobody tested whether their backup actually restores. Nobody scrubbed a calling list against the do-not-call register before dialling. Nobody spent an afternoon writing a one-page assessment of who might use their platform and what could go wrong for them. None of these are expensive or technical fixes — they're closer to habits than to security budgets. If you run a small business, the return on investment here is enormous relative to the cost: test your backup restore process at least once, check any marketing list against the relevant preference service before you use it, and before you launch anything that collects personal data — especially from people who might be under 18 — spend twenty minutes writing down what you're collecting, why, and what the worst case looks like if it goes wrong. That habit of pausing to ask "have we actually checked this, or are we assuming it's fine?" is the one thing every case above has in common.

ICO fines & breach roundup — 6 July 2026

A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.


1. National ransomware warning — 323 UK organisations hit in a year, over half small businesses (campaign launched 29 June 2026)

On 29 June 2026, Report Fraud (the UK's national fraud and cyber-crime reporting service, run with police and the National Cyber Security Centre) launched a campaign warning that 323 organisations reported a ransomware attack to police between April 2025 and March 2026 — and more than half of those, 175 reports, came from small and medium-sized enterprises. Reported financial losses totalled around £270,000, a 50% increase on the year before, with manufacturing, scientific/technical services and education among the hardest-hit sectors. This isn't an ICO fine or a single named breach — it's a national advisory, and the real figures are almost certainly higher since businesses often under-report losses. But it's directly relevant here: it confirms that ransomware isn't just a large-company problem, and that UK authorities are actively telling SMEs to prepare and report.

What your business should learn: The advice from the National Cyber Security Centre and UK law enforcement is not to pay a ransom — paying doesn't guarantee you get your data back and funds the next attack. The cheap, practical preparation is a tested backup that's kept offline or otherwise unreachable by an attacker who's already inside your network, so a ransomware infection is an inconvenience rather than a catastrophe. Actually test that you can restore from it — a backup nobody has ever restored from is a hope, not a plan. And know in advance who you'd call (Report Fraud, your insurer, an IT contact) so a bad day doesn't start with a panicked search for a phone number.


2. Energy Prices Direct Limited — £160,000 (announced May 2026), 700,000+ unwanted marketing calls

The ICO fined Glasgow-based energy-buying consortium Energy Prices Direct Limited £160,000 after it made more than 700,000 unsolicited marketing calls over a roughly 12-month period (January 2024 to January 2025) to numbers registered with the Telephone Preference Service (TPS) and Corporate TPS — the official do-not-call lists — in breach of the Privacy and Electronic Communications Regulations (PECR). The ICO's investigation also found that in some calls, staff failed to properly identify themselves as calling on the company's behalf.

What your business should learn: PECR consent rules aren't just about email and text — they cover phone calls too. If your business (or a marketing agency or call centre acting for you) cold-calls prospects, you must screen numbers against the TPS/CTPS lists before dialling, and every caller should clearly identify who they're calling from. This is a cheap, mechanical check — a list-scrub before a campaign goes out — and it's exactly the kind of basic compliance step the ICO expects even from smaller outbound-sales operations.


3. MediaLab (Imgur owner) — £247,590 (February 2026), first fine under the Children's Code

The ICO fined MediaLab.AI, Inc., owner of the image-hosting site Imgur, £247,590 — its first financial penalty under the UK's Children's Code. Over a four-year period (September 2021 to September 2025), the ICO found MediaLab had no age-assurance measures in place, processed the personal data of children under 13 without parental consent or another lawful basis, and hadn't carried out a data protection impact assessment (DPIA) even though children were foreseeably using the platform and could be exposed to harmful content.

What your business should learn: If your website, app or online community could realistically be used by under-13s — a forum, a comments section, an image or video sharing feature, even a general-audience app with no age gate — you're in scope of the Children's Code, regardless of your size. Before you build or launch something like this, do a short DPIA (a one-page "what data do we collect, who might use this, what could go wrong" document is a legitimate start) and add basic age-assurance rather than treating age as self-declared and unchecked. It's a lot cheaper to think about this before launch than to retrofit it after four years of use.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Compiled from public ICO enforcement notices and UK data-protection news. For awareness only — not legal advice, and not affiliated with the ICO. Always check the ICO's own published notices for the authoritative detail.