Hazard

Reprimands · Online technology and telecoms

Gain Capital UK Limited

No fineReprimands
Root cause Unpatched or unsupported software A known vulnerability was left unfixed, or the software was past end of support. The most directly preventable cause on this list.

What happened

Gain Capital UK have been issued a Reprimand in respect of Articles 32 (2) and 32 (1) (b). An unauthorised third party leveraged an unpatched software vulnerability to access Gain Capital’s systems and exfiltrate personal data relating to 72,361 UK Data Subjects. Gain Capital had a support contract in place with a third party whom they believed were responsible for notifying Gain Capital about software security updates, however the contract stipulated that upgrades were Gain Capital’s responsibility.

Summarised from the notice published by the ICO on 10 March 2023. Read the original notice — it is the authoritative version.

The other end of this

This action came down to software left unfixed. These vulnerabilities are confirmed exploited and already past their remediation deadline.

All exploited vulnerabilities →