Lessons to learn from a year of data breaches
In the year since the HMRC data breach, many more have been made public – here’s a roundup of 11 lessons (we should have) learned.


Or that's what a few organisations learned this year.
An Oxford man bought a computer on eBay for just 35. Quite a bargain, given it held the banking details, credit card numbers and even signatures of a million people. Apparently, the device was sold by an "ex-employee" of digital document company Graphic Data.
Kirklees Council found itself the subject to a potential data breach after a virtual private network (VPN) server a supplier previous used was sold on eBay for just 99p. Not only did the buyer win the Cisco equipment for one heck of a discount, but security codes were still programmed onto the device when it was hooked up, it reconnected to the council's private servers without any prompting. Whoops.
Another savvy shopper got more than they bargained for via the auction site after successfully bidding on a second-hand camera for just 17. Not only did the buyer win a Nikon digital camera, but also a memory card complete with photos and documents relating to suspected terrorists being investigated by the device's previous owner, MI6. James Bond would be ashamed.
Lesson Nine: Shopping online isn't perfectly safeNo, it's not time to panic. The vast majority of online transactions are carried out without any trouble at all. But when it goes bad, it can be ugly, as mail order clothing retailer Cotton Traders found this summer.
Hackers managed to steal the credit card details of as many as 38,000 customers from the online clothing shop, including enough information to leave people open to card not present' fraud.
And although the attack happened in January, customers were not alerted to it until June. How many of them do you think will do their Christmas shopping online this year?
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Indeed, a survey by Symantec suggested 93 per cent of people wouldn't hand over the details to a firm which had already had a breach makes you wonder what the other seven per cent are thinking?
Lesson 10: Data breaches can cost you. A lot.According to research by the Ponemon Institute, the average cost of a data breach by record is 47.
About half of that cost is from lost business, with the rest from detection, notification, and cleaning up after the fact such as issuing new account cards or helping victims avoid fraud. Based on the study, the 25 million records lost by HMRC cost some 625 million.
At the time, Quocirca's Bob Tarzey said: "There is no evidence that the HMRC data loss last year cost anything it terms of the data actually being use to exploit tax payers as it is not even clear that the data reached the public domain, however, the cost to HMRCs reputation was immense, if it had been a company this may well have led to a share price drop."
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
Meta just revived plans to train AI models using European user data
News Meta has confirmed plans to train AI models using European users’ public content and conversations with its Meta AI chatbot.
By Nicole Kobie
-
AI is helping bad bots take over the internet
News Automated bot traffic has surpassed human activity for the first time in a decade, according to Imperva
By Bobby Hellard
-
New Zealand privacy commissioner tipped to become next ICO head
News John Edwards is said to be an 'anti-Facebook' regulator who would fit well in the UK's plans to clamp down on big tech
By Bobby Hellard
-
What is a freedom of information (FOI) request?
In-depth We look at the mechanism citizens can use to hold public bodies to account
By Dale Walker
-
ICO hints at Facebook hypocrisy over data protection goals
News Elizabeth Denham asks Facebook to drop appeal after CEO's call for greater internet regulation
By Bobby Hellard
-
ICO to investigate Google over GDPR violations
News UK Watchdog to liaise with other European regulators over 'forced consent' push by the tech giant
By Bobby Hellard
-
ICO myth-busts on the flow of data post Brexit
News The Information Commissioner explains how data will move between the UK and EU in a no-deal scenario
By Bobby Hellard
-
Leave.EU faces big fine over data law breaches
News Information commissioner reveals Leave.EU was fined a total of £75,000 for “serious breaches”
By Alan Martin
-
ICO website knocked offline for more than 24 hours
News The outage was caused by an “unprecedented electrical surge” that damaged its host’s circuits
By Keumars Afifi-Sabet
-
Elizabeth Denham appointed ICO boss
News Denham will be tasked with helping the UK leave the EU without any knock-on effects on privacy
By Clare Hopping