Chartered Institute for Securities & Investment
Disclosed Feb 21, 20233 years agoConfirmed
UK ICO reprimand for security failings
An unauthorised third party exploited a known vulnerability in the Sitefinity software to leverage a bruteforce attack to upload a malicious code to the Chartered Institute for Securities & Investment (CISI)’s website checkout page. The code captured payment details of an estimated 3,883 UK Data Subjects, as well as other personal data including names and email addresses. CISI instructed a third party to conduct a forensic investigation which found that CISI were running unsupported software which had a number of vulnerabilities, one of which was a critical vulnerability for which a security patch had been available since 2017. CISI also advised that no penetration tests had been conducted prior to the incident, and that 654 Data Subjects had reported fraudulent activities on the payment cards affected by the incident. CISI may have missed opportunities to identify the data breach earlier, as a number of individuals had reported card fraud prior to a group notification 14 April 2020, at which point CISI conducted a full investigation.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Feb 21, 2023 |
| Attack | Vendor breach |
| Data exposed | Not stated |
| Sector | Nonprofit · GB |
| Status | Confirmed |
| Lawsuit or fine | UK ICO reprimand (2023-02-21) |
Sources
| Source | |
|---|---|
| UK ICO reprimand: Chartered Institute for Securities & Investmentico.org.uk · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| UK ICOregulator:GB | Feb 21, 2023 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (UK ICO), confirmed by UK ICO. Record counts are as reported. Not legal advice.
Everything about Chartered Institute for Securities & Investment