Reprimands · Finance insurance and credit
Optionis Group Limited
No fineReprimands
Root cause
Ransomware
An attacker encrypted or stole data and demanded payment. Usually the visible end of a chain that started with an unpatched service or a stolen credential.
What happened
The data controller suffered a ransomware attack, which resulted in the exfiltration of personal data. A reprimand was issued in respect of specific infringements of the UK GDPR, which include lack of multi-factor authentication, an inadequate account lockout policy, and no clear Bring Your Own Device policy.
Summarised from the notice published by the ICO on 10 October 2023. Read the original notice — it is the authoritative version.
The other end of this
Ransomware crews get in somehow. These are vulnerabilities CISA has tied directly to ransomware campaigns — each one is a live route into an organisation like this one.
- CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability Broadcom · VMware vCenter
- CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability Cisco · Secure Firewall Management Center (FMC)
- CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability SonicWall · SMA1000 Appliances
- CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability SonicWall · SMA1000 Appliances
- CVE-2026-45659 Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability Microsoft · SharePoint Server