Cathay Pacific fined $639,000 in UK over data-security lapses

Cathay Pacific Airways was fined 500,000 pounds by the UK’s privacy watchdog for failing to protect customers’ data due to security lapses lasting nearly four years. The penalty is the highest the UK authority could levy under old rules that were replaced in May 2018 with tougher measures boosting regulators’ fining powers. Between October 2014 and May 2018, Cathay Pacific’s computer systems “lacked appropriate security measures which led to customers’ personal details being exposed, 111,578 of whom were from the UK, and approximately 9.4m more worldwide,” the UK Information Commissioner’s Office said Wednesday. “This breach was particularly concerning given the number of basic security inadequacies across Cathay Pacific’s system, which gave easy access to the hackers,” Steve Eckersley, the ICO’s director of investigations, said in the statement. “The multiple serious deficiencies we found fell well below the standard expected.” The airline is held responsible for failing to prevent “the unauthorized access to their passengers’ personal details,” including names, passport and identity details, the ICO added.<br/>
Bloomberg
https://www.bloomberg.com/news/articles/2020-03-04/cathay-pacific-fined-639-000-in-u-k-over-data-security-lapses
3/4/20