Western Mail

Dixons hit by hackers in a major breach

- HOLLY WILLIAMS newsdesk@walesonlin­e.co.uk

DIXONS Carphone has become the latest British firm to fall victim to a cyber attack after revealing 5.9 million customer bank card details and 1.2 million personal data records were hacked.

The retailer behind Currys said that while 5.8 million of the payment cards targeted were protected by chip and pin, around 105,000 non-EU cards without chip and pin protection were compromise­d.

Dixons Carphone said relevant card companies had been notified, but added that there was no evidence of fraud on the cards as a result of the incident.

It added that its investigat­ion had also found that hackers accessed nonfinanci­al personal data – such as name, address or email details – for 1.2 million customer records.

The group is contacting all those affected, but sought to assure customers it had no evidence that this had resulted in fraud at this stage.

It said it had called in cyber experts and added extra security to its systems following the breach, while also since calling in the police and relevant authoritie­s.

Dixons Carphone chief executive Alex Baldock admitted the group had “fallen short” of its responsibi­lity to protect customer data.

The National Crime Agency said that it is working with the National Cyber Security Centre, the Financial Conduct Authority and the Informatio­n Commission­er’s Office (ICO) to “understand what’s happened”.

A spokesman for the ICO said: “An incident involving Dixons Carphone has been reported to us and we are liaising with the National Cyber Security Centre, the Financial Conduct Authority and other relevant agencies to ascertain the details and impact on customers.

“Anyone concerned about lost data and how it may be used should follow the advice of Action Fraud.”

Dixons Carphone was fined £400,000 by the ICO in January after a 2015 cyber attack exposed the personal data of more than three million customers.

The latest data breach began in July last year, well before May 25, when new European General Data Protection Regulation (GDPR) rules came into force. It means that Dixons Carphone will likely escape hefty fines under the new regime, which can be up to €20m for a significan­t data breach.

However, the ICO said that it is still determinin­g whether the case is dealt with under the 1998 or 2018 Data Protection Act.

Dixons Carphone shares fell as much as 4% soon after the London market opened.

Mr Baldock added: “We are extremely disappoint­ed and sorry for any upset this may cause.

“The protection of our data has to be at the heart of our business, and we’ve fallen short here.

“We’ve taken action to close off this unauthoris­ed access and, though we have currently no evidence of fraud as a result of these incidents, we are taking this extremely seriously.”

Dixons said the hack occurred in one of the processing systems of Currys PC World and Dixons Travel stores.

 ??  ?? > Dixons Carphone has admitted a huge data breach
> Dixons Carphone has admitted a huge data breach

Newspapers in English

Newspapers from United Kingdom