Sunday, May 25, 2025
HomeCyber Security NewsNorthern Ireland Police to Pay £750,000 Fine Following Data Breach

Northern Ireland Police to Pay £750,000 Fine Following Data Breach

Published on

SIEM as a Service

Follow Us on Google News

The Police Service of Northern Ireland (PSNI) has been ordered to pay a £750,000 fine following a significant data breach last year.

The breach involved the accidental release of the personal details of 9,400 officers and staff. Despite representations to the Information Commissioner’s Office (ICO) to reduce the penalty, the fine remains unchanged.

Details of the Data Breach

In August last year, the PSNI inadvertently published sensitive information under a Freedom of Information (FOI) request.

- Advertisement - Google News

This included personnel’s surnames, initials, ranks, and roles. The data was available online for several hours before removal but not before dissident Republicans obtained it.

The UK’s Information Commissioner, John Edwards, labeled this incident “the worst data breach” his office encountered.

He emphasized the severe impact on PSNI officers and staff, many of whom had taken measures to conceal their employment due to security concerns.

Analyse Any Suspicious Links Using ANY.RUN’s New Safe Browsing Tool: Try for Free

Financial Implications for PSNI

According to the BBC report, Chief Constable Jon Boutcher regretted the fine, highlighting its impact on the PSNI’s strained budget.

The service faces a £34 million shortfall, and Boutcher noted that the penalty would “further compound” financial challenges. He stated that the PSNI has implemented measures to mitigate risks and protect its workforce since the breach.

These include crime prevention advice and support for officers and their families. 

The ICO had initially considered a £5.6 million fine but reduced it in recognition of the organization’s public nature. Despite this concession, the £750,000 fine is still the largest ever imposed on a public body in the UK.

Reactions and Accountability

The Police Federation also voiced disappointment over the financial penalty. Chairman Liam Kelly argued that funds could have been better allocated to enhance data security and invest in community initiatives like road safety and CCTV partnerships.

However, Information Commissioner John Edwards maintained that accountability has been upheld even if no individual job losses occurred.

He reiterated that his role is to protect information rights through appropriate fines. The incident underscores the critical importance of robust data management practices within public bodies, especially those handling sensitive information. 

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Free Registration

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Zero-Trust Policy Bypass Enables Exploitation of Vulnerabilities and Manipulation of NHI Secrets

A new project has exposed a critical attack vector that exploits protocol vulnerabilities to...

Threat Actor Sells Burger King Backup System RCE Vulnerability for $4,000

A threat actor known as #LongNight has reportedly put up for sale remote code...

Chinese Nexus Hackers Exploit Ivanti Endpoint Manager Mobile Vulnerability

Ivanti disclosed two critical vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager...

Hackers Target macOS Users with Fake Ledger Apps to Deploy Malware

Hackers are increasingly targeting macOS users with malicious clones of Ledger Live, the popular...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Zero-Trust Policy Bypass Enables Exploitation of Vulnerabilities and Manipulation of NHI Secrets

A new project has exposed a critical attack vector that exploits protocol vulnerabilities to...

Threat Actor Sells Burger King Backup System RCE Vulnerability for $4,000

A threat actor known as #LongNight has reportedly put up for sale remote code...

Chinese Nexus Hackers Exploit Ivanti Endpoint Manager Mobile Vulnerability

Ivanti disclosed two critical vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager...