Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

May 10th, 2011, 18:03 GMT · By

Owner of Former Speculative Invoicing Firm Fined over Data Breach

SHARE:

Adjust text size:


ACS:Law former boss fined by ICO
Enlarge picture
Andrew Crossley, the former owner of ACS:Law, a legal firm that engaged in speculative invoicing, was fined by the Information Commissioner's Office for failing to adequately protect personal data.

Speculative invoicing is the still on-going practice of sending letters to file sharers suspected of copyright infringement and threatening them with legal action unless they pay a sum to settle accusations.

ACS:Law was one of the firms that pioneered speculative invoicing in UK and was one of the first targets of Anonymous' Operation Payback DDoS campaigns back in September 2010.

At around the same time, members of the hacktivist collective discovered an archived email backup left unprotected on the company's website and uploaded it on The Pirate Bay.

Some of the emails in the leaked database had Excel spreadsheets attached which contained the personal information of over 5,000 file sharers the company obtained from ISPs.

The Information Commissioner's Office launched an investigation into the matter which was finalized yesterday with a fine of £1,000 against Andrew Crossley.

Crossley was fined personally because ACS:Law went bankrupt earlier this year. ICO notes that had the company not ceased trading, the penalty could have reached £200,000 given the severity of the breach.

"Sensitive personal details relating to thousands of people were made available for download to a worldwide audience and will have caused them embarrassment and considerable distress.

"The security measures ACS Law had in place were barely fit for purpose in a person’s home environment, let alone a business handling such sensitive details," said Information Commissioner Christopher Graham. [pdf]

ICO determined that ACS:Law didn't ask for professional advice when setting up its IT system that lacked firewalls and access controls. In addition, the Web hosting package it used for its website was destined for home users.

The ICO also investigated BT for sending personal information about its customers to ACS Law in unencrypted format, but it determined that it was an employee's mistake. The decision to drop that investigation was strongly criticized by privacy watchdogs.

TELL US WHAT YOU THINK:

893 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


ICO Criticized for Dropping Investigation into BT Data Breach

ACS:Law Faces Huge Fine Over Extensive Data Breach

ACS:Law Leaked Emails Might Violate Consumer Privacy

Anonymous Leaks ACS:Law Emails via The Pirate Bay

Law Firm Attacked as 4Chan DDoS Campaign Continues

READER COMMENTS:


Comment #1 by: Eric on 11 May 2011, 19:10 UTC reply to this comment

It does feel nice for this guy to get what he deserves...anyone engaging in speculative invoicing has no ethics and is just looking to make money. Since that's all he cares about, it is nice to see him take a slight hit in the wallet!

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM