• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

LNER customer data loss

Status
Not open for further replies.

Halwynd

Member
Joined
11 Sep 2021
Messages
554
Location
North West
LNER have just updated their notice about this which gives some additional information which might provide clues for our forum IT experts?

Purely as a precaution, some of our customer communications have temporarily been paused including;

  • LNER Assistant, our direct messaging service which provides live updates about your journey, such as platform information and delay updates. To check for the latest update to your service please visit our Travel Updates page and search for your journey.
  • Automated Delay Repay (One Click Delay Repay) emails. If you have been delayed by 30+ minutes between 10 September and now, please submit your claim manually which can be done here: LNER Delay Repay – Make a claim
  • Confirmation emails once a Delay Repay Claim has been approved. However you can check the status of your Delay Repay claim via your LNER Account.

 
Last edited by a moderator:
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

185

On Moderation
Joined
29 Aug 2010
Messages
5,709
LNER is a state run company.

The third party private company supplier must be named - the state shouldn't allowing them any privacy.
 

dcsprior

Member
Joined
28 Aug 2012
Messages
862
Location
Edinburgh (Fri-Mon) & London (Tue-Thu)
It's about time these companies were fined £x for every piece of customer data they allow to be compromised - it's the only way they'll learn.

The Co-op allowed my data to be breached and I no longer shop with them. I now no longer trust LNER and the same will apply.

I don't think fining a company for being a victim of crime is morally right.

Imagine that a bank who was held up by armed robbers had to pay a fine because of it.

In both cases, there's always more that can be done to improve security, and in both cases it's effectively impossible to achieve 100% security without.

So in my opinion, fines should only be for clear-cut cases of negligence.
 
Joined
1 Nov 2021
Messages
305
Location
Berwick
I don't think fining a company for being a victim of crime is morally right.

Imagine that a bank who was held up by armed robbers had to pay a fine because of it.

In both cases, there's always more that can be done to improve security, and in both cases it's effectively impossible to achieve 100% security without.

So in my opinion, fines should only be for clear-cut cases of negligence.
Having poor security/passwords for your system is surely a case of ‘gross negligence’? I know that when I put a SAP system whilst it was being built the backdoor access had a password of admin. The first thing I changed when I found out about that backdoor.
 

35B

Established Member
Joined
19 Dec 2011
Messages
5,362
Having poor security/passwords for your system is surely a case of ‘gross negligence’? I know that when I put a SAP system whilst it was being built the backdoor access had a password of admin. The first thing I changed when I found out about that backdoor.
We don't know what happened here, nor do we know whether it was "poor security" or not. In just the same way, a house being burgled doesn't necessarily mean that it has poor security
 

dcsprior

Member
Joined
28 Aug 2012
Messages
862
Location
Edinburgh (Fri-Mon) & London (Tue-Thu)
Having poor security/passwords for your system is surely a case of ‘gross negligence’? I know that when I put a SAP system whilst it was being built the backdoor access had a password of admin. The first thing I changed when I found out about that backdoor.

In cases where it's clear negligence then yes.

But not automatically in all cases where there's a data breach.

In other words: pretty much what it is just now.
 

duffield

Established Member
Joined
31 Jul 2013
Messages
3,268
Location
East Midlands
...
The thing I find strange is being told to have a very hard to crack password, that contains various symbols and characters etc.
But I am not sure who's benefit this is for, as most sites if you try a numbers of times and fail, you are locked out and have to reset anyway.
Most passwords and logins are stolen via the companies network, so what is the point in making it overly complicated, better to have lots of unique simple ones.
Although many companies still require or recommend some of special characters, numbers, mixed case etc., it's not the current advice from security professionals. As far as I remember the current advice is to use a string of random but easy to remember words, the classic illustrative example being "correcthorsebatterystaple". No special characters, no capitalisation, no spaces, easy to type. This is the pattern I use on sites that I care about and which allow it (e.g. Amazon).

Many people also swear by password managers where you can have a randomly generated password that you don't even know, but that can get complicated with multiple devices and very awkward if you lose access to your password vault or need to sign on unexpectedly on (e.g.) a friend or family member's device.

Of course, the trend is to move away from passwords to biometrics and validation devices or applications, combined with a PIN. "Something you are, something you possess, and something you know". Many workplaces have adopted this partly or fully; before I retired in 2019 my workplace had our building access cards doubling as validation devices which slotted into your PC, so effectively you could not leave your PC unlocked.
 

jumble

Established Member
Joined
1 Jul 2011
Messages
1,483
no, "or", it'll always be "and" - because whether or not they pay the ransom, they'd still be legally obliged to report the breach so are likely to be fined anyway.

== Doublepost prevention - post automatically merged: ==


that's already an option - just like any other kind of punishment. And it happens, e.g. this company was fined ~£3m (~£40 per item of data) for a data breach: https://ico.org.uk/action-weve-taken/enforcement/2025/03/advanced-computer-software-group-limited/, and the MOD were fined ~£1300 per email address leaked in this instance: https://ico.org.uk/action-weve-taken/enforcement/ministry-of-defence-1/
How useful that the ICO fines the MOD
As The ICO hand over the money to the government and the government fund the MOD who now need more money to pay the fine the money goes in a big circle
 

enginedin

Member
Joined
15 Dec 2020
Messages
473
Location
UK
How useful that the ICO fines the MOD
As The ICO hand over the money to the government and the government fund the MOD who now need more money to pay the fine the money goes in a big circle
well, I know - but there's always that argument for any fines to any public sector organisation
 

185

On Moderation
Joined
29 Aug 2010
Messages
5,709
At present, I'm involved with an investigation into a major data breach at three operators (concerning staff matters) and it's interesting to see how differently the operators have behaved since the start. Only one has admitted they were at fault.

One of the others sent the name and home address details of 25 staff to a member of the public. A third was caught retaining ex employee data for 15 years after initially denying it.

Those hacking data are criminals - absolutely, however companies which fail to lock the back door or don't think GDPR applies to them are equally criminally responsible by their sloppy negligence.
 
Last edited:

yorkie

Forum Staff
Staff Member
Administrator
Joined
6 Jun 2005
Messages
78,186
Location
Yorkshire
It's about time these companies were fined £x for every piece of customer data they allow to be compromised - it's the only way they'll learn.
Is that the third party company? I don't necessarily disagree, but how would you define a "piece" of data?
 

MrJeeves

Established Member
Associate Staff
Senior Fares Advisor
Joined
28 Aug 2015
Messages
4,609
Location
Burgess Hill
At least M&S and the Co-op apologised, LNER can't even be bothered to say sorry.
Typically, that apology comes after they know exactly what to apologise for. That usually takes a week or two as they trawl through systems to see what was stored on them, and what has evidence of being accessed.
 

Halwynd

Member
Joined
11 Sep 2021
Messages
554
Location
North West
Is that the third party company? I don't necessarily disagree, but how would you define a "piece" of data?

I gave my data to LNER and my contract is with them alone, any penalties should be paid by them. A piece of data would be a name, an address, an email address or a telephone number - there will be other examples - just as you enter it when registering for an account. Another option I'd consider would be a legal requirement for the company to whom the customer has provided their data, in this case LNER, to provide those whose data has been compromised with a credit and identity monitoring service for a given period of time. This already happens in some cases, but is not a legal requirement. Some companies would need to take out insurance against this which might then have the benefit of further process oversight by the underwriters. Of course, the company involved may then take legal action against the company to whom they have outsourced whatever the function to recover these costs.

Typically, that apology comes after they know exactly what to apologise for. That usually takes a week or two as they trawl through systems to see what was stored on them, and what has evidence of being accessed.

That's OK, but LNER passed my data to the company which breached it, nobody else, surely a simple and general 'We're sorry this has happened...' would be just common courtesy pending the release any further details?
 
Last edited:

tumbledown

Member
Joined
5 Nov 2024
Messages
271
Location
UK
I gave my data to LNER and my contract is with them alone, any penalties should be paid by them.
No, if LNER exercised due diligence in choosing a contractor and has a suitable contract and data-transfer protocol in place with them, LNER is not legally responsible for the data loss. The ICO can pursue the contractor if they are at fault, and order compensation etc.
That's OK, but LNER passed my data to the company which breached it, nobody else, surely a simple and general 'We're sorry this has happened...' would be just common courtesy pending the release any further details?
Agreed, just as "we apologise for the delay to your journey today" doesn't imply fault.
 

BlueLeanie

On Moderation
Joined
21 Jul 2023
Messages
723
Location
Haddenham
No, if LNER exercised due diligence in choosing a contractor and has a suitable contract and data-transfer protocol in place with them, LNER is not legally responsible for the data loss. The ICO can pursue the contractor if they are at fault, and order compensation etc.

Agreed, just as "we apologise for the delay to your journey today" doesn't imply fault.

When I order an item on-line and the courier damages it, I don't sue the courier, I make a claim against the company that sold me the goods.

If I buy a new vacuum cleaner from Argos, and it fails within 3 months, I don't contact the vacuum manufacturing company. Argos refund me immediately, and fine the supplier.

My contract isn't with the Oursourced Digital Co, my contract is with LNER. The outsourced company may be fined by ICO (if they are in the UK), but it's up to LNER to compensate me for the terrible failure of their contractors and to counter sue the contractors if necessary.
 

tumbledown

Member
Joined
5 Nov 2024
Messages
271
Location
UK
My contract isn't with the Oursourced Digital Co, my contract is with LNER.
Which specific clause of your contract with LNER do you think has been broken?
From the ICO Guidance

Can you be held liable for non-compliance?​

Yes. You are ultimately accountable for your own compliance and the compliance of your processors.
You will be liable for any damage (and any associated claim for compensation payable to an individual) if your processing activities infringe the UK GDPR.

However, you are not liable for damage resulting from a breach of the UK GDPR if you can prove you were not in any way responsible for the event giving rise to the damage.
Link
 

BlueLeanie

On Moderation
Joined
21 Jul 2023
Messages
723
Location
Haddenham
Guidance is the important word.

Should I return the $2,500 in compensation I received from a US Bank, with offices in London, when one of their Delaware based contractors shared (inaccurate) data about me with a Philippines based marketing company?

(It took a lot of effort to trace it.)
 

tumbledown

Member
Joined
5 Nov 2024
Messages
271
Location
UK
We have provisionally decided to fine Advanced Computer Software Group Ltd (Advanced) £6.09m, following an initial finding that the provider failed to implement measures to protect the personal information of 82,946 people, including some sensitive personal information.

Advanced provides IT and software services to organisations on a national scale, including the NHS and other healthcare providers, and handles people’s personal information on behalf of these organisations as their data processor...
Here's a concrete example of a provisional decision against a data processor which leaked NHS data. Note that there is no mention of so much as a reprimand against the NHS. The ICO has found against the NHS in cases where NHS Staff have been at fault.

Banks are governed by specific legislation, and US law may have taken precedence.

Also, responsibility for accuracy of personal data and for not agreeing to it being sent to a country where inadequate data protection exists always remains with the entity collecting the data - sending inaccurate data to the Philippines would break UK law twice over.
 
Last edited by a moderator:

Tetchytyke

Veteran Member
Joined
12 Sep 2013
Messages
17,443
Location
Isle of Man
We don't know what happened here, nor do we know whether it was "poor security" or not. In just the same way, a house being burgled doesn't necessarily mean that it has poor security
Indeed.

A company can have the best security in the world but humans are fallible and humans make mistakes. That’s why scammers increasingly target the weak link in any computer system- the person sitting in the chair. IT people laugh about PICNIC- problem in chair, not in computer- for a reason.

A certain amount of data theft is inevitable. The simple truth is that the scammers only have to get lucky once, whereas the company has to be lucky every day.

My interest is in how companies handle it afterwards. Transparency has to be the key. I’m not sure that clobbering everyone who has a data breach would encourage such transparency.
 
Joined
14 Jun 2022
Messages
45
Location
Yorkshire
I received an email from the Data Protection Officer telling me I was affected on Friday. Doesn’t look to be a formatted mailshot email, it looks like it’s been sent individually. It contains an apology, a brief summary, says reported to nation cyber security centre, police and the ico. It says they were given an affected data set on Friday 12th, and it looks like someone has stayed up late on Friday 12th emailing people. I emailed back on Saturday with some questions and received a response from the Data Protection Officer a couple of hours later.

Looks like their team isn’t having a weekend and whilst I’m bothered - do you know anyone else who would have emailed late at night on the same day they got a list of affected people?
 

Halwynd

Member
Joined
11 Sep 2021
Messages
554
Location
North West
Indeed.

A company can have the best security in the world but humans are fallible and humans make mistakes. That’s why scammers increasingly target the weak link in any computer system- the person sitting in the chair. IT people laugh about PICNIC- problem in chair, not in computer- for a reason.

A certain amount of data theft is inevitable. The simple truth is that the scammers only have to get lucky once, whereas the company has to be lucky every day.

My interest is in how companies handle it afterwards. Transparency has to be the key. I’m not sure that clobbering everyone who has a data breach would encourage such transparency.

On the face of it, what you say is entirely reasonable.

The M&S data loss was caused by a breach at their outsourced IT helpdesk - Tata Consultancy - and that cost them £300 million, not to mention all the reputational damage.

Companies need to improve their systems, take a dual key approach to more functions, and use outsourcing only if there is no other option. One of my previous bosses once said to me: you only outsource if you don't care. I think he had a point.
 

BlueLeanie

On Moderation
Joined
21 Jul 2023
Messages
723
Location
Haddenham
Here's a concrete example of a provisional decision against a data processor which leaked NHS data. Note that there is no mention of so much as a reprimand against the NHS. The ICO has found against the NHS in cases where NHS Staff have been at fault.

Banks are governed by specific legislation, and US law may have taken precedence.

Also, responsibility for accuracy of personal data and for not agreeing to it being sent to a country where inadequate data protection exists always remains with the entity collecting the data - sending inaccurate data to the Philippines would break UK law twice over.
US Federal or US State law didn't matter, they had an office in London.

It was better value for them to say "oops, sorry, would $2,500 close the case?" than to deal with both the FOS and the ICO at the same time.

Surprisingly, the level of Spam I received for the next 6 months or so dropped to a trickle.
 
Joined
5 Jan 2014
Messages
565
I do make shopping decisions based on things like this to an extent, but if I avoided every retailer which had suffered a data breach, I'd probably starve.

Co-op, M&S, Tesco, Asda, Sainsbury's have all had data breaches in the past decade.
You could always just buy things in person
 

35B

Established Member
Joined
19 Dec 2011
Messages
5,362
I do all my grocery shopping in store but obviously use Nectar, Sparks etc
Which it's worth noting is some of the most intrusive data gathering that commercial companies undertake.
 
Status
Not open for further replies.

Top