ICO fines & breach roundup — 15 July 2026
A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.
1. Thermotech Wall and Loft Surveys Ltd & Jacksons Marketing Ltd — £370,000 combined (8 July 2026), scare-tactic nuisance calls to vulnerable people
The ICO fined two home-improvement marketing companies a combined £370,000 for making hundreds of thousands of unlawful marketing calls to numbers registered with the Telephone Preference Service (TPS) — the official do-not-call list. Thermotech Wall and Loft Surveys Ltd (TWLS) was fined £240,000 after making around 575,000 calls over a six-month period using "Avatar" robo-call software routed through an overseas call centre; Jacksons Marketing Ltd (JML) was fined £130,000 for more than 230,000 calls over 11 months. Both companies shared the same director, Thomas Vickrage of Bournemouth, who the ICO found was also directing JML's activities. The calls falsely told recipients their existing loft insulation could be "hazardous to health and dangerous" and that their details had been provided by the government — neither was true — and one disabled older woman reported being frightened by the calls. WhatsApp messages uncovered in the investigation showed Vickrage encouraging the overseas call centre to keep dialling TPS-registered numbers. Both firms were also issued enforcement notices ordering them to stop.
What your business should learn: Screening a calling or texting list against the TPS/CTPS registers before you dial is a cheap, mechanical step, and "we didn't know the number was listed" doesn't hold up once regulators see hundreds of thousands of calls to registered numbers. The bigger lesson is about tone: a marketing script that manufactures fear ("this could be dangerous," "the government gave us your details") to pressure someone into engaging is a red flag on its own, well before you even get to consent law — if you wouldn't want a regulator reading your call script back to you, don't use it. And if you run more than one company, expect a regulator to treat you as one operation if the same person is directing both.
2. Cumbria Constabulary launches a ransomware advice campaign for schools, small businesses and charities (5 July 2026)
Cumbria Police's Cyber and Digital Crime Unit launched a county-wide ransomware awareness campaign aimed specifically at schools, small businesses, charities, hospitality venues (pubs among them) and residents — the force's first operation of this kind — after what officers describe as a sustained rise in cyber-extortion attempts against organisations that typically have no dedicated IT security resource. One officer said: "Ransomware attacks can cause serious disruption — locking systems, halting operations and risking sensitive data. However, there are practical steps every organisation can take to reduce risk and recover quickly if an incident occurs." Nationally, the National Cyber Security Centre recorded over 400 ransomware incidents affecting UK organisations in the year to May 2026, with education accounting for nearly a quarter of them; charities and small hospitality businesses are said to be hit disproportionately often, in part because they tend to run on legacy Windows installations or consumer-grade routers left on default passwords. This isn't an ICO fine — it's a police advisory — but it's a direct, current signal from UK law enforcement about who's actually being targeted.
What your business should learn: If you run a small business, school, club or charity with no dedicated IT person, you are exactly the profile this campaign is describing, not too small to be worth a criminal's time. The advice on offer is unglamorous and free: turn on multi-factor authentication everywhere it's available, don't click unsolicited links, keep an offline backup of anything you couldn't bear to lose, and change any router or admin password still left on its factory default. If an attack does happen, UK businesses and charities can report it 24/7 via Report Fraud (0300 123 2040) — and the guidance is consistent with every prior case in this series: don't pay the ransom.
3. Fortray Global Services — a UK managed-IT and cybersecurity provider claimed as a ransomware victim (10 July 2026, unconfirmed)
On 10 July 2026 the ransomware group "TheGentlemen" listed Fortray Global Services Limited — a UK IT company that sells managed IT services, endpoint/XDR security and security-operations-centre monitoring to other businesses — on its dark-web leak site, claiming to have compromised the company and threatening to publish stolen data if it isn't paid. Important caveat: at the time of writing, this is a claim made by the criminal group, tracked by ransomware/threat-intelligence monitoring services, not a breach confirmed by Fortray itself — the company has not issued a public statement, so treat the scope and details as unverified. It's included here because of what it represents rather than what's confirmed: TheGentlemen is one of the most active ransomware groups of 2026, and it's a pointed reminder when the claimed target is itself in the business of selling cybersecurity and managed IT services to others.
What your business should learn: If you outsource IT support, security monitoring or hosting to a managed service provider, that provider's security is now part of your own risk — a breach at your IT supplier can expose your data even if your own systems were never touched, exactly as the Capita and DPP Law cases in earlier roundups showed. A company's name or marketing containing the word "security" is not evidence its internal practices meet that standard. Ask any IT or security supplier directly: do you enforce MFA on your own admin tools, do you keep each client's environment segmented from the others, and is there a contractual commitment to tell us quickly if something goes wrong on your end? If they can't answer plainly, that's your answer.
Sources
- ICO — Enforcement action
- ICO — Two home improvement companies fined £370,000 for nuisance calls targeting vulnerable people
- DecisionMarketing — Two firms spanked for torrent of scare-mongering calls
- Cumbria Constabulary — Cumbria Police digital experts offer countywide advice to protect against ransomware
- Times and Star — Schools, businesses offered ransomware advice by police
- DeXpose — TheGentlemen Ransomware Group Strikes Fortray Global Services (claim, unconfirmed by the company)