• News/
  • https://www.theregister.com/2025/11/06/why_uk_businesses_paying/

Why UK businesses are paying ICO millions for password mistakes you're probably making right now

The Register
·
Eirik Salmi, system analyst, Passwork
·
Published Nov 6, 2025
·
Updated

Partner Content UK GDPR Article 32 mandates "appropriate security measures". The ICO has defined what that means: multi-million-pound fines for password failures. The violations that trigger them? Small, familiar, and happening in your organization right now. Your sysadmin shares SSH keys via WhatsApp in "defnotsshkeys.txt". Your HR manager stores employee ID scans in Gmail. Your intern has admin access because it was easier than configuring permissions. And your former contractor from 2017 still receives reports with client data because his email was never removed from the distribution list. These scenarios range from the simplest to more complex, like misconfigured cloud storage with cascading access rights across departments. But they share a common outcome: this is exactly how cybersecurity breaches happen. And when they do, ICO responds with fines that can cripple businesses. Capita plc just learned this expensive lesson — unsecured AWS buckets and extractable passwords cost them £14 million. The pattern continues across industries: Advanced Computer Software received a £3.07 million fine for incomplete MFA coverage. 23andMe paid £2.31 million after credential stuffing attacks exploited password reuse. Even small firms like DPP Law Ltd faced a £60,000 penalty when a brute-force attack breached an admin account that lacked MFA protection. The statutory maximum? Four percent of worldwide annual revenue. For a mid-sized UK business with £10 million turnover, that's a potent...

Read full article

Affected Software

1 affected component
AWS S3
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses UK businesses facing significant fines from the ICO due to password management failures.

2

What security implications are discussed in relation to password management?

The article highlights that improper password practices can lead to breaches of UK GDPR and hefty financial penalties.

3

What specific violations contribute to these fines?

Common violations include sharing SSH keys via insecure channels like WhatsApp.

4

Which software is mentioned as being affected by these security issues?

AWS S3 is identified as one of the software products affected by password management failures.

5

How are UK businesses responding to these GDPR-related fines?

UK businesses are paying millions of pounds due to non-compliance with security measures mandated by GDPR.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203