ICO fines & breach roundup — 16 September 2026
A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.
No new ICO fine or reprimand was published in the week to 16 September. What the week did produce is arguably more useful to a small business: a breach in which every technical control worked exactly as designed and the data still walked out of the door, a £26m settlement over data shared with advertising partners, and a newly opened ICO investigation into something every organisation has to do and most do badly.
1. Revolut handed customers' passports, selfies and transaction histories to a fraudster — because the email passed every authentication check
On 11 September Revolut began writing to customers to tell them their personal data had been disclosed to an unauthorised third party; the company confirmed the incident publicly on Saturday 12 September. The mechanism is the part worth reading twice. Someone sent Revolut requests for customer information from a mailbox on a genuine government domain — reporting says the messages carried valid SPF, DKIM and DMARC results, because they really were sent from that domain — and Revolut staff processed them as ordinary legal-compliance requests of the kind a regulated bank receives constantly. The data handed over included names, dates of birth, occupations, postal and email addresses, phone numbers and copies of identity documents such as passports and driving licences, and for some customers verification selfies, account statements, IBANs and full transaction histories. Revolut has not published a number: it says only that it has "contacted the limited number of impacted individuals directly", and figures that have circulated in coverage — around 680, or the Financial Times' "nearly 700" — are reporting the company has not confirmed. Revolut says customer funds were not touched, and it describes the episode as a "sophisticated external impersonation scam" rather than a compromise of its systems. Several things are genuinely unresolved and should not be smoothed over: Revolut has not named the government body whose domain was used, nor explained how the mailbox came to be under an attacker's control, and the precise mix of data varies from customer to customer. A group calling itself "Revolut Smilik" has claimed responsibility, published some of the data and is demanding a ransom of 10,000 Bitcoin while threatening daily releases — that is the extortionists' own account and their claims about what they hold are unverified. On the regulatory side an ICO spokesperson said only that it has "received a report and [is] assessing the information provided", and the Financial Conduct Authority is engaging with the firm. No finding, investigation outcome or penalty exists, and none should be assumed.
What your business should learn: Email authentication proves where a message came from. It proves nothing about whether the request inside it is lawful, or whether the person typing it is who the mailbox says they are — and this is the case that shows the gap, because Revolut's technical controls all passed. You will get far cruder versions of the same thing: a solicitor's office asking you to confirm a client's address, "HMRC" asking for payroll details, a supplier's finance team asking you to update their bank account, a police-sounding request for CCTV or customer records. The habit that stops all of them costs nothing: for any request to hand over personal data or move money, call back on a number you look up yourself — from the organisation's own published website or a previous invoice — never a number, link or reply address in the message itself, and never in the same thread. Write that down as a one-line rule, tell whoever handles your inbox that they will never be criticised for the delay it causes, and make sure they know that "it looked completely genuine" is the expected outcome, not a reason to skip the call.
2. Grindr to pay £26m to settle a UK group claim over data allegedly shared with advertising partners
Not an ICO case, but the biggest UK data-protection money of the month and the clearest warning yet about what your website and app quietly send to third parties. Grindr agreed on 2 September to pay £26m (about $35m) to settle a group action at the High Court of England and Wales, disclosing the agreement to investors two days later in a filing with the US Securities and Exchange Commission; it was widely reported over the following week. The claim, issued by law firm Austen Hays in April 2024 on behalf of around 12,000 UK users, alleged that the app unlawfully processed personal data and shared highly sensitive information — including users' HIV status and last test date, sexual orientation and GPS location — with advertising and analytics companies without adequate consent, in the period up to the start of 2020, when Grindr was under different ownership. The settlement contains no finding or admission of liability; Grindr continues to dispute the allegations while acknowledging the distress and loss of trust expressed by some UK users about that period, and says it stopped sharing HIV status with third parties back in 2018. Payment is in two instalments, £13m by the end of December 2026 and £13m by the end of March 2027; if divided equally that would be roughly £2,167 per claimant, though the distribution method has not been confirmed. The company was separately fined 65m Norwegian krone (about £4.8m) by Norway's data protection authority in 2021 over related consent failings, upheld on appeal in October 2025.
What your business should learn: Every advertising pixel, analytics script, chat widget and marketing SDK on your site is a third party you are sending customer data to, and in law you are the one who has to justify it. Almost nobody can list them. Spend twenty minutes doing it: open your site in a browser, use the developer tools' network tab (or a free privacy-scanning tool) to see which outside domains it contacts, and write the list down. Then ask two questions of each one — can I say what this collects, and would a customer be surprised? — and delete the ones that fail. Be strictest about anything that could reveal something sensitive: health, sexuality, religion, trade union membership, finances. A page URL alone can do it, because "/clinic/hiv-testing" or "/debt-advice" in an analytics feed says as much as a tick-box would. This is the cheapest fix on the whole compliance list — it is deleting code, not buying anything — and it is the one most likely to be sitting on your site right now.
3. ICO opens an investigation into Police Scotland over how it handles subject access requests
On 11 September the ICO published a statement confirming it has opened an investigation into Police Scotland's handling of subject access requests (SARs) — the right anyone has to ask an organisation for a copy of the personal information it holds about them. The regulator says it is seeking to establish whether the force has failed, or is failing, to comply with its obligations under Articles 12 and 15 of the UK GDPR and section 45 of the Data Protection Act 2018, including whether it responds within the statutory timescale. Police Scotland's own website tells requesters that "due to unprecedented demand" the current wait can be up to nine months, that requests are dealt with in date order, and that it endeavours to meet the one-calendar-month deadline for straightforward cases. The ICO was explicit that opening an investigation means it has reached no conclusion and that the statement is not intended to predetermine the outcome — so there is no finding and no penalty here, and it should not be reported as one. It is also a separate matter from the £66,000 fine and reprimand the ICO issued to the force in March 2026 over the mishandling of a victim's mobile phone data.
What your business should learn: A SAR is free for the person asking, requires no particular form of words — "can you send me everything you have on me?" in an email is a valid one — and is one of the few obligations where the clock is short and the failure is entirely visible from outside. For an ordinary business the deadline is one calendar month, extendable by up to two further months only where the request is genuinely complex or you have received several, and only if you tell the person within the first month that you are extending and why. The reason organisations miss it is almost never refusal; it is that the email lands in a shared inbox, nobody recognises what it is, and six weeks vanish. Three cheap fixes: tell whoever reads your general inbox what a SAR looks like so it is spotted on day one; name one person responsible and put a calendar reminder at day 21, not day 30; and write down now where personal data actually lives — email, accounting system, CRM, the shared drive, the booking system, backups — because assembling that list under a deadline is what turns a routine request into a missed one. And note the direction of travel: if a police force gets an investigation over timescales, a small company with a backlog has no better excuse.
Sources
- The Register — Revolut falls for fake government requests, hands over customer data
- TechCrunch — Revolut confirms customer data breach through fake government requests
- Infosecurity Magazine — Revolut Confirms Data Breach Through Fake Government Requests
- Help Net Security — What we know about the Revolut data breach so far
- TechRadar — Revolut sent identity data, contact details, and documents to hackers posing as a government agency
- Malwarebytes — Revolut gave customer IDs and financial data to a government impostor
- Disruption Banking — Revolut Breach Escalates as Attackers Threaten to Release More Customer Data
- The Register — Grindr pays £26M to settle UK privacy class action
- Infosecurity Magazine — Grindr Settles UK Data Privacy Claims for £26m
- Privacy Laws & Business — Grindr agrees to pay £26m to settle UK group litigation
- The Hacker News — Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
- ICO — Statement on its investigation into Police Scotland
- Police Scotland — Subject Access Requests
- ICO — Police Scotland fined £66k and reprimanded following serious data mishandling
- ICO — Enforcement action