Reprimands · Online technology and telecoms
Gain Capital UK Limited
What happened
Gain Capital UK have been issued a Reprimand in respect of Articles 32 (2) and 32 (1) (b). An unauthorised third party leveraged an unpatched software vulnerability to access Gain Capital’s systems and exfiltrate personal data relating to 72,361 UK Data Subjects. Gain Capital had a support contract in place with a third party whom they believed were responsible for notifying Gain Capital about software security updates, however the contract stipulated that upgrades were Gain Capital’s responsibility.
Summarised from the notice published by the ICO on 10 March 2023. Read the original notice — it is the authoritative version.
The other end of this
This action came down to software left unfixed. These vulnerabilities are confirmed exploited and already past their remediation deadline.
- CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability Check Point · SmartConsole
- CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft · SharePoint
- CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability WordPress · Core
- CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability Langflow · Langflow
- CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability DD-WRT · DD-WRT