HomeSecurityHMRC: Concerns about personal data breaches

HMRC: Concerns about personal data breaches

A series of data breaches at HM Revenue & Customs (HMRC) last year has raised concerns about customer security

HMRC

According to its most recent annual report, the company reported 11 data breach incidents to the Information Commissioner's Office for the 2019/20 financial year.

In one case, almost 19,000 of its members were potentially affected when incorrect details were sent with HMRC National Insurance letter numbers, involving 16-year-olds.

Meanwhile in February, an attack led to the leak of details about 64 employees from three PAYE schemes, including names, contact details and data such as usernames and passwords.

Also over the summer, a staff member's data was compromised whendocuments were left on a train, including medical notes and HR letters.

Cybersecurity expert Tim Sadler, CEO of security firm Tessian, said the human factor was often the main cause of a data breach.

Mr Sadler said: “Given that people are in control of more data than ever before, it is not surprising that security incidents caused by human error are on the rise.”

“It is therefore the responsibility of an organization to ensure that it puts solutions in place to avoid mistakes that compromise cybersecurity – warning people about their mistakes before they do something they will regret.”

HMRC: Concerns about personal data breaches

In its latest annual report, HMRC also reported 15 centralised security incidents involving protected personal data in 2019/20, potentially affecting 3,616 customers.

Donal Blaney, director of Griffin Law, said: “Taxpayers have the right to expect that their sensitive personal data will be kept secure by the company.”

“The Information Commissioner should immediately investigate HMRC for these breaches and hold it to account for this astonishing incompetence.”

Jim Harra, chief executive of HMRC, said in the report that the company serves millions of customers each year and has tens of millions of printed and electronic interactions with them.

Mr. Harra said: “We take the issue of data security extremely seriously and are constantly striving to improve the security of customer information.”

“We investigate and analyze all security incidents to understand and mitigate information security risk. We learn and act on our incidents.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS