Skip to content

Optionis Group

Disclosed Oct 10, 20232 years agoConfirmed

Official notice

UK ICO reprimand for security failings

The data controller suffered a ransomware attack, which resulted in the exfiltration of personal data. A reprimand was issued in respect of specific infringements of the UK GDPR, which include lack of multi-factor authentication, an inadequate account lockout policy, and no clear Bring Your Own Device policy.

What is known

People affectedNot stated in the sources we have
DisclosedOct 10, 2023
AttackRansomware
Data exposedNot stated
SectorFinance · GB
StatusConfirmed
Lawsuit or fineUK ICO reprimand (2023-10-10)

Sources

Source
UK ICO reprimand: Optionis Group Limitedico.org.uk · Regulator

Notices filed

WhereFiledPeople
UK ICOregulator:GBOct 10, 2023
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (UK ICO), confirmed by UK ICO. Record counts are as reported. Not legal advice.

Everything about Optionis Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.