A UK local authority disclosed personal data during its complaints-handling process after forwarding complaints to a councillor with all complainants’ identifying details included, despite some complainants opting to withhold their names. The information reportedly exposed included sensitive contact details (e.g., home addresses, email addresses, phone numbers) that would not normally be shared with the subject of a complaint, raising a data protection breach and governance concerns around how complaint records are processed and redacted.
Separately, the UK Information Commissioner’s Office (ICO) won a court battle in its long-running attempt to uphold a £500,000 fine against DSG Retail (owner of Currys PC World and Dixons Travel) tied to a major 2017 breach in which malware was installed on 5,390 point-of-sale tills and remained undetected for nine months. The incident involved theft of 5.6 million payment card numbers and expiry dates (without cardholder names) and personal data relating to roughly 14 million individuals; a central legal dispute is whether the payment card data alone constitutes personal data under the applicable pre-GDPR regime. A third item argues for using tax incentives (modeled on green-energy policy) to drive “security by design” and improve cybersecurity outcomes, but it is a policy opinion piece rather than reporting on a specific incident or enforcement action.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
After discovering the disclosure, Dulcie Tudor said she notified the Information Commissioner's Office on behalf of the complainants. At the time, the council had not explained the cause of the breach or whether it had self-reported the incident.
Cornwall Council sent councillor Dulcie Tudor complaint materials that included the names and contact details of all ten complainants, including four who had chosen to withhold their identities. Tudor said she then shared the materials with the Free Speech Union as part of her response, further widening exposure.
By February 2026, the UK Court of Appeal ruled in favor of the ICO, rejecting the view that identifiability should be judged from the attacker's perspective. The court held that DSG's ability as controller to link the data to individuals meant the compromised card data could qualify as personal data, and sent the case back to the First-tier Tribunal.
In 2020, the UK Information Commissioner's Office fined DSG Retail £500,000 under the Data Protection Act 1998 for security failings tied to the 2017 breach. The case focused in part on whether stolen card numbers and expiry dates qualified as personal data.
In 2017, malware on thousands of point-of-sale tills at Currys PC World and Dixons Travel led to the compromise of payment card data and other personal information affecting millions of records. The incident later became the basis for enforcement action by the UK Information Commissioner's Office.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcego.theregister.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.