grc-scanSecurity & governance
ICO watch · UK16 September 2026Archived edition

ICO fines & breach roundup

This edition was published on 16 September 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest roundup for the current picture.

The takeaway

None of this week's cases began with a hacked system — each one started with a routine process, from answering an official request to sharing data with an advertising partner, that nobody had ever checked.

  • Verify any request to hand over personal data by calling back on a number you looked up yourself, never one in the message.
  • List every third party your website sends visitor data to, and delete the ones you cannot justify.
  • Name one person for data requests from customers and diary them at three weeks — the legal deadline is one month.

ICO fines & breach roundup — 16 September 2026

A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.

No new ICO fine or reprimand was published in the week to 16 September. What the week did produce is arguably more useful to a small business: a breach in which every technical control worked exactly as designed and the data still walked out of the door, a £26m settlement over data shared with advertising partners, and a newly opened ICO investigation into something every organisation has to do and most do badly.


1. Revolut handed customers' passports, selfies and transaction histories to a fraudster — because the email passed every authentication check

On 11 September Revolut began writing to customers to tell them their personal data had been disclosed to an unauthorised third party; the company confirmed the incident publicly on Saturday 12 September. The mechanism is the part worth reading twice. Someone sent Revolut requests for customer information from a mailbox on a genuine government domain — reporting says the messages carried valid SPF, DKIM and DMARC results, because they really were sent from that domain — and Revolut staff processed them as ordinary legal-compliance requests of the kind a regulated bank receives constantly. The data handed over included names, dates of birth, occupations, postal and email addresses, phone numbers and copies of identity documents such as passports and driving licences, and for some customers verification selfies, account statements, IBANs and full transaction histories. Revolut has not published a number: it says only that it has "contacted the limited number of impacted individuals directly", and figures that have circulated in coverage — around 680, or the Financial Times' "nearly 700" — are reporting the company has not confirmed. Revolut says customer funds were not touched, and it describes the episode as a "sophisticated external impersonation scam" rather than a compromise of its systems. Several things are genuinely unresolved and should not be smoothed over: Revolut has not named the government body whose domain was used, nor explained how the mailbox came to be under an attacker's control, and the precise mix of data varies from customer to customer. A group calling itself "Revolut Smilik" has claimed responsibility, published some of the data and is demanding a ransom of 10,000 Bitcoin while threatening daily releases — that is the extortionists' own account and their claims about what they hold are unverified. On the regulatory side an ICO spokesperson said only that it has "received a report and [is] assessing the information provided", and the Financial Conduct Authority is engaging with the firm. No finding, investigation outcome or penalty exists, and none should be assumed.

What your business should learn: Email authentication proves where a message came from. It proves nothing about whether the request inside it is lawful, or whether the person typing it is who the mailbox says they are — and this is the case that shows the gap, because Revolut's technical controls all passed. You will get far cruder versions of the same thing: a solicitor's office asking you to confirm a client's address, "HMRC" asking for payroll details, a supplier's finance team asking you to update their bank account, a police-sounding request for CCTV or customer records. The habit that stops all of them costs nothing: for any request to hand over personal data or move money, call back on a number you look up yourself — from the organisation's own published website or a previous invoice — never a number, link or reply address in the message itself, and never in the same thread. Write that down as a one-line rule, tell whoever handles your inbox that they will never be criticised for the delay it causes, and make sure they know that "it looked completely genuine" is the expected outcome, not a reason to skip the call.


2. Grindr to pay £26m to settle a UK group claim over data allegedly shared with advertising partners

Not an ICO case, but the biggest UK data-protection money of the month and the clearest warning yet about what your website and app quietly send to third parties. Grindr agreed on 2 September to pay £26m (about $35m) to settle a group action at the High Court of England and Wales, disclosing the agreement to investors two days later in a filing with the US Securities and Exchange Commission; it was widely reported over the following week. The claim, issued by law firm Austen Hays in April 2024 on behalf of around 12,000 UK users, alleged that the app unlawfully processed personal data and shared highly sensitive information — including users' HIV status and last test date, sexual orientation and GPS location — with advertising and analytics companies without adequate consent, in the period up to the start of 2020, when Grindr was under different ownership. The settlement contains no finding or admission of liability; Grindr continues to dispute the allegations while acknowledging the distress and loss of trust expressed by some UK users about that period, and says it stopped sharing HIV status with third parties back in 2018. Payment is in two instalments, £13m by the end of December 2026 and £13m by the end of March 2027; if divided equally that would be roughly £2,167 per claimant, though the distribution method has not been confirmed. The company was separately fined 65m Norwegian krone (about £4.8m) by Norway's data protection authority in 2021 over related consent failings, upheld on appeal in October 2025.

What your business should learn: Every advertising pixel, analytics script, chat widget and marketing SDK on your site is a third party you are sending customer data to, and in law you are the one who has to justify it. Almost nobody can list them. Spend twenty minutes doing it: open your site in a browser, use the developer tools' network tab (or a free privacy-scanning tool) to see which outside domains it contacts, and write the list down. Then ask two questions of each one — can I say what this collects, and would a customer be surprised? — and delete the ones that fail. Be strictest about anything that could reveal something sensitive: health, sexuality, religion, trade union membership, finances. A page URL alone can do it, because "/clinic/hiv-testing" or "/debt-advice" in an analytics feed says as much as a tick-box would. This is the cheapest fix on the whole compliance list — it is deleting code, not buying anything — and it is the one most likely to be sitting on your site right now.


3. ICO opens an investigation into Police Scotland over how it handles subject access requests

On 11 September the ICO published a statement confirming it has opened an investigation into Police Scotland's handling of subject access requests (SARs) — the right anyone has to ask an organisation for a copy of the personal information it holds about them. The regulator says it is seeking to establish whether the force has failed, or is failing, to comply with its obligations under Articles 12 and 15 of the UK GDPR and section 45 of the Data Protection Act 2018, including whether it responds within the statutory timescale. Police Scotland's own website tells requesters that "due to unprecedented demand" the current wait can be up to nine months, that requests are dealt with in date order, and that it endeavours to meet the one-calendar-month deadline for straightforward cases. The ICO was explicit that opening an investigation means it has reached no conclusion and that the statement is not intended to predetermine the outcome — so there is no finding and no penalty here, and it should not be reported as one. It is also a separate matter from the £66,000 fine and reprimand the ICO issued to the force in March 2026 over the mishandling of a victim's mobile phone data.

What your business should learn: A SAR is free for the person asking, requires no particular form of words — "can you send me everything you have on me?" in an email is a valid one — and is one of the few obligations where the clock is short and the failure is entirely visible from outside. For an ordinary business the deadline is one calendar month, extendable by up to two further months only where the request is genuinely complex or you have received several, and only if you tell the person within the first month that you are extending and why. The reason organisations miss it is almost never refusal; it is that the email lands in a shared inbox, nobody recognises what it is, and six weeks vanish. Three cheap fixes: tell whoever reads your general inbox what a SAR looks like so it is spotted on day one; name one person responsible and put a calendar reminder at day 21, not day 30; and write down now where personal data actually lives — email, accounting system, CRM, the shared drive, the booking system, backups — because assembling that list under a deadline is what turns a routine request into a missed one. And note the direction of travel: if a police force gets an investigation over timescales, a small company with a backlog has no better excuse.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Compiled from public ICO enforcement notices and UK data-protection news. For awareness only — not legal advice, and not affiliated with the ICO. Always check the ICO's own published notices for the authoritative detail.