ICO fines Cathay Pacific £500,000 for 2018 data breach
Hong Kong airline hit with maximum fine under the Data Protection Act 2018 for "basic" security failures


The Information Commissioner's Office (ICO) has fined Hong Kong airline Cathay Pacific £500,000 for failing to protect the data of approximately 9.4 million people in 2018.
From October 2014 to May 2018, the airline's computer systems lack basic security measures, according to the ICO, which led to customer's personal data being exposed.
An ICO investigation found that Cathay Pacific had failed to secure its computer systems and allowed unauthorised access to personal details such as names, passport and identity data, dates of birth, postal and email addresses, phone numbers and also historic travel records.
Of the 9.4 million customers who had their data exposed, 111,578 were from the UK, but due to the timing of the breach, the company has received a maximum monetary fine under the Data Protection Act 2018, rather than the GDPR.
"This breach was particularly concerning given the number of basic security inadequacies across Cathay Pacific's system, which gave easy access to the hackers," said Steve Eckersley, ICO director of investigations.
"The multiple serious deficiencies we found fell well below the standard expected. At its most basic, the airline failed to satisfy four out of five of the National Cyber Security Centre's basic Cyber Essentials guidance."
The airline hired a cyber security firm after noticing suspicious activity in March 2018. The incident was then reported to the ICO by the company Cathay had hired. In its investigation, the ICO found that its systems were entered via a server connected to the internet where malware was installed to harvest data.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
An investigation quickly followed and the data watchdog said it found a "catalogue" of errors, such as back-up files without passwords, unpatched internet-facing servers, unsupported operating systems and inadequate antivirus software.
Responding to the ICO's notice, Cathay Pacific told IT Pro that it had already taken measures to enhance its IT security in areas such as data governance, network security and access control, education and employee awareness, and incident response agility.
"Substantial amounts have been spent on IT infrastructure and security over the past three years and investment in these areas will continue," the airline said. "We have co-operated closely with the ICO and other relevant authorities in their investigations."
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
CISA issues warning in wake of Oracle cloud credentials leak
News The security agency has published guidance for enterprises at risk
By Ross Kelly
-
Reports: White House mulling DeepSeek ban amid investigation
News Nvidia is caught up in US-China AI battle, but Huang still visits DeepSeek in Beijing
By Nicole Kobie
-
ICO admits it's too slow dealing with complaints – so it's eying up automation to cut staff workloads
News The UK's data protection authority has apologized for being slow to respond to data protection complaints, saying it's been overwhelmed by increased workloads.
By Emma Woollacott
-
“Limited resources” scupper ICO probe into EasyJet breach
News The decision to drop the probe has been described as “deeply concerning” by security practitioners
By Ross Kelly
-
Surge in workplace monitoring prompts new ICO guidelines on employee privacy
News Detailed guidance on how to implement workplace monitoring could prevent data protection blunders
By Ross Kelly
-
TikTok could be hit with £27m fine for failing to protect children's privacy
News Social media firm issued with a notice from the ICO for potential violations of UK data protection laws
By Bobby Hellard
-
What is AdTech and why is it at the heart of a regulation storm?
In-depth The UK data regulator has come under heavy fire for consistently delaying much-needed action, privacy groups say
By Carly Page
-
ICO crackdown on AI recruitment part of three-year vision to save businesses £100 million
News ICO25 outlines a fresh approach that involves releasing learning materials, advice, and a new ICO-moderated discussion forum for businesses
By Connor Jones
-
Clearview AI fined £7.5m over improper use of UK data
News Australian facial recognition firm collected 20 billion images from the internet without consent in order to build its database
By Bobby Hellard
-
UK data watchdog cut IT spending by £1.2 million during pandemic
News The ICO’s IT budget has been slashed by around 23% since 2019
By Sabina Weston