A Herefordshire Council employee, Geoffrey Smith, received a suspended prison sentence after unlawfully accessing about 490 sensitive personal records and downloading 94 documents over four days while working in the council's Children and Young People directorate. The records belonged to family members and other people known to him, and included highly sensitive information such as medical records, social worker reports, and child and family assessments involving adults and children.
Smith pleaded guilty to an offence under Section 1 of the UK Computer Misuse Act 1990, and Worcester Magistrates' Court sentenced him to two months' imprisonment suspended for 12 months. The court also ordered 120 hours of unpaid work, £2,000 in costs, and a £154 victim surcharge, while the Information Commissioner's Office said the case reflected a systematic misuse of authorized access given the sensitivity of the data involved.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
At Worcester Magistrates' Court, Smith was sentenced to two months' imprisonment suspended for 12 months for the unlawful access. The court also imposed 120 hours of unpaid work, about £2,000 in costs, and a victim surcharge.
Smith admitted an offence under Section 1 of the UK Computer Misuse Act 1990 for the unauthorized access to the council records. The plea was cited in reporting on the case and sentencing.
While working in Herefordshire Council's Children and Young People directorate, Geoffrey Smith accessed about 490 records and downloaded 94 documents belonging to family members and other acquaintances over a four-day period. The data included medical records, social worker reports, and child and family assessments involving adults and children.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.