grc-scanSecurity & governance
ICO watch · UK29 July 2026Archived edition

ICO fines & breach roundup

This edition was published on 29 July 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest roundup for the current picture.

The takeaway

Not one of this week's cases needed a sophisticated attacker: a call list nobody screened, a password reused from a personal account, a response nobody had planned. The basics existed — they just weren't turned on.

  • Screen every outbound call and text list against the TPS register before a campaign; that is where six-figure fines start.
  • Turn on multi-factor authentication everywhere, and never reuse a password between personal and work accounts.
  • Write down now who you call and what you say first, so criminals' unverified claims can't set your response later.

ICO fines & breach roundup — 29 July 2026

A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.


1. Two home-improvement marketing firms fined £370,000 for nuisance calls targeting vulnerable people

The ICO announced in July 2026 that it had fined two connected home-improvement marketing firms a combined £370,000 for making hundreds of thousands of unlawful calls to numbers registered with the Telephone Preference Service (TPS) — people who had explicitly said they did not want to be contacted. Thermotech Wall and Loft Surveys Ltd was fined £240,000 after making 575,062 unsolicited calls over a six-month period (1 October 2024 to 31 March 2025) about loft insulation, home surveys and "government grants," much of it via "Avatar" robo-call software run through overseas call centres. Jacksons Marketing Ltd was fined £130,000 for more than 230,000 similar calls over 11 months. The same Bournemouth-based individual, Thomas Vickrage, was a director of the first firm and is suspected of directing the second. The ICO's finding on why this specifically targeted "vulnerable people": call recipients reported being told their existing insulation was hazardous to their health, and that their personal details had come from the government — both claims the regulator found to be false, a classic pressure tactic aimed at older or anxious homeowners. Both companies also received enforcement notices ordering them to stop.

What your business should learn: This is a PECR (marketing-consent) case, not a hacking case, and it's exactly the kind of enforcement an ordinary SME is actually at risk of — not a nine-figure tech fine. If you or a marketing agency you use makes outbound sales calls or sends bulk texts/emails, you must screen against the TPS/CTPS register unless you hold clear, specific, recorded consent from that exact person for that exact type of contact — a "yes" buried in someone else's terms and conditions, or bought from a third-party list, doesn't count. It costs nothing to check your own call/text lists against the TPS register before a campaign, and it is far cheaper than a six-figure fine.


2. Craneware update: an extortion group now claims responsibility — treat the claim with caution

Last week's roundup covered Craneware plc, the Edinburgh healthtech firm that disclosed unauthorised access to part of its systems on 20 July 2026. Since then, an extortion group calling itself "Chaos" listed Craneware on its dark-web leak site (spotted by ransomware-tracking services on 28 July 2026), claiming to have exfiltrated internal files. This has not been independently confirmed — the posting does not quantify what was taken or provide proof, Craneware has not (at time of writing) confirmed the Chaos group specifically as the attacker, and security researchers have separately noted that Chaos-attributed leak-site listings have in the past included exaggerated or unverified claims. Craneware's own public statements continue to describe most of the exposed material as "non-sensitive or already-public," alongside a smaller set of genuine employee and customer/partner records.

What your business should learn: If your business is ever named — accurately or not — on a criminal extortion site, don't let the criminals' claims dictate your response. These listings exist to pressure victims into paying, and the group's own numbers and descriptions are not evidence; they're a negotiating tactic. The right response is the boring one: your own forensic review (or your insurer/IR provider's) of what was actually accessed, a decision on regulatory notification based on that review — not on what the criminals say — and public statements that stick to what you actually know. Promising you'll "never pay" or panicking and paying immediately are both worse than pausing to find out what's true first.


3. accesso Technology Group named by an extortion group using stolen "infostealer" logins, not hacking

accesso Technology Group, a Surrey-headquartered ticketing and guest-experience software provider used by theme parks, attractions and entertainment venues, was listed on the leak site of an extortion group calling itself "coinbasecartel" around 28 July 2026, which claims to hold stolen company data. As with the Craneware case above, this is an unverified criminal claim — accesso has not issued a public statement confirming or denying it at the time of writing, and it should be treated as unconfirmed. What makes this group worth flagging regardless of whether this specific claim holds up: security researchers describe coinbasecartel as skipping traditional hacking or file-encrypting ransomware entirely, instead buying up "infostealer" credential logs — usernames and passwords harvested by malware from employees' personal or work devices — and simply logging in to cloud storage, FTP servers and file-sharing services with valid stolen passwords.

What your business should learn: This attack method defeats most of the security spending a small business typically prioritises (firewalls, antivirus, patching) because the attacker doesn't need a vulnerability — just a password that already works. Two cheap, concrete defences: (1) turn on multi-factor authentication on every cloud, admin and file-sharing account you use, with no exceptions, so a leaked password alone isn't enough to get in; and (2) use a password manager and never reuse a password between personal accounts and work systems — infostealer malware very often infects a personal device first, and the stolen password only becomes a business problem if it's also your work password. A free periodic check of your company's email domain on a breach-monitoring site (such as Have I Been Pwned) costs nothing and can surface a compromised account before it's used against you.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Compiled from public ICO enforcement notices and UK data-protection news. For awareness only — not legal advice, and not affiliated with the ICO. Always check the ICO's own published notices for the authoritative detail.