The Information Commissioner’s Office (ICO) has fined Merseyside-based law firm DPP Law Ltd £60,000 following a cyber attack that compromised sensitive personal data.
Key Points:
- Nature of the Breach: In June 2022, cyber attackers accessed DPP’s network through an administrator account lacking multi-factor authentication (MFA), exploiting a brute-force attack. This led to the theft of over 32GB of data, including highly sensitive and legally privileged information, which was later found on the dark web.
- ICO Findings: The ICO determined that DPP failed to implement appropriate security measures to protect personal data, particularly given the sensitive nature of their legal work. The firm also delayed reporting the breach, notifying the ICO 43 days after being informed by the National Crime Agency.
- Legal Obligations: Organisations are legally required to safeguard personal data by implementing robust cyber security measures, such as MFA, regular vulnerability assessments, and timely security updates.
- ICO’s Message: The ICO emphasised that data protection is a legal obligation, and failures can result in significant financial and reputational consequences.
For more detailed information, you can read the ICO’s full monetary penalty notice here.



