UK's information regulator fines Carphone Warehouse £400K over preventable 2015 breach that exposed 3M+ customer details
LONDON (Reuters) - Britain's information regulator said on Wednesday it had fined Carphone Warehouse 400,000 pounds ($539,400) after a 2015 cyber attack exposed …
Context & Ripple Effects
The fine closes out an arc that began when hackers were reported to have accessed details of 2.4M Carphone Warehouse customers plus 90K encrypted credit card records in August 2015; the regulator now puts the final exposure above 3 million and calls the breach preventable. The £400K penalty lands under the ICO's pre-GDPR regime, where the statutory maximum is £500K — a ceiling that Equifax and Facebook both hit later in 2018 before British Airways' proposed £184M GDPR-era fine showed how much larger the stakes would get.
First-order effects
- Carphone Warehouse pays £400,000 ($539,400) for security failures the ICO judged preventable, on top of three years of remediation and reputational cost since the 2015 attack became public.
Second-order effects
- The ruling signals to every UK data holder that 'preventable' is the ICO's trigger word: within months, Equifax was fined the full £500,000 over its 2017 breach affecting ~15M Britons, and Facebook took the same maximum over Cambridge Analytica.
Third-order effects
- Under the old £500K cap these fines were symbolic; once GDPR-style penalties arrive — British Airways' breach fine initially proposed at ~£184M before the ICO cut it to £20M — enforcement becomes material to balance sheets and negotiable, turning breach-response quality into a priced compliance function rather than an IT line item.
The trend: UK data-protection enforcement is scaling from capped six-figure penalties toward large, discretionary GDPR-era fines, making preventable breaches a board-level financial risk.