Gain Capital UK
Disclosed Mar 10, 20233 years agoConfirmed
UK ICO reprimand for security failings
Gain Capital UK have been issued a Reprimand in respect of Articles 32 (2) and 32 (1) (b). An unauthorised third party leveraged an unpatched software vulnerability to access Gain Capital’s systems and exfiltrate personal data relating to 72,361 UK Data Subjects. Gain Capital had a support contract in place with a third party whom they believed were responsible for notifying Gain Capital about software security updates, however the contract stipulated that upgrades were Gain Capital’s responsibility.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Mar 10, 2023 |
| Attack | Vendor breach |
| Data exposed | Not stated |
| Sector | Tech · GB |
| Status | Confirmed |
| Lawsuit or fine | UK ICO reprimand (2023-03-10) |
Sources
| Source | |
|---|---|
| UK ICO reprimand: Gain Capital UK Limitedico.org.uk · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| UK ICOregulator:GB | Mar 10, 2023 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (UK ICO), confirmed by UK ICO. Record counts are as reported. Not legal advice.