Optionis Group
Disclosed Oct 10, 20232 years agoConfirmed
UK ICO reprimand for security failings
The data controller suffered a ransomware attack, which resulted in the exfiltration of personal data. A reprimand was issued in respect of specific infringements of the UK GDPR, which include lack of multi-factor authentication, an inadequate account lockout policy, and no clear Bring Your Own Device policy.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Oct 10, 2023 |
| Attack | Ransomware |
| Data exposed | Not stated |
| Sector | Finance · GB |
| Status | Confirmed |
| Lawsuit or fine | UK ICO reprimand (2023-10-10) |
Sources
| Source | |
|---|---|
| UK ICO reprimand: Optionis Group Limitedico.org.uk · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| UK ICOregulator:GB | Oct 10, 2023 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (UK ICO), confirmed by UK ICO. Record counts are as reported. Not legal advice.