us

216.73.217.135

Back
News

UK Fines Dixons Carphone for Massive Breach

UK Fines Dixons Carphone for Massive Breach
R Richard M. JANUARY 13, 2020 1 minute read

Dixons Carphone is one of the largest electronics and phone retailers in the UK. Recently British regulators have fined the company £500,000 ($653,000) because of the data breach that exposed millions of the customers’ records.

According to the Information Commissioner’s office, Dixons has violated the U.K’s data protection act 1988. The company had poor security arrangements and failed to take proper steps to protect personal data. In its report, ICO claimed regarding inappropriate measures that

“This included vulnerabilities such as inadequate software patching, absence of a local firewall, and lack of network segregation and routine security testing”

Dixons Carphone is also known as DSG retail and has stores in eight countries; this is the second time in two years that DSG has been fined. Firstly, it was fined £400,000 ($523,000) in January 2018 for the 2015 breach of its carphone warehouse subsidiary. In the breach, the attacker exploited an outdated WordPress installation.

Dixons’ breach began in July 2017 and persisted until April 2018, which means before the enforcement of GDPR in May 2018. Hence it avoided the larger fine that would have imposed under EU’s strict GDPR privacy law. The organizations can face fines up to 4 percent of the annual global revenue. But in Dixon’s case, the regulators applied the previous protection law which allowed a maximum fine of £500,000. 

As per ICO’s investigation, in the breach, the attackers installed malware in 5,390 e-cash registers accross the company’s stores. The malware exploited the personal information of 14 Million individuals nd collected details of 5.6 million payment cards. The exposed information included full names, emails, postcodes and failed credit checks from internal services.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.