3 ms·
From the article, it sounds like this was earlier in the year, but they're only revealing it now? Isn't that way beyond the deadline for such things?
by eterm 1y ago
From the article, it sounds like this was earlier in the year, but they're only revealing it now? Isn't that way beyond the deadline for such things?
- deleted 1y ago[deleted]
- akerl_ 1y agoDoes the UK actually have a mandated deadline for any kind of infosec disclosure?
- arethuza 1y agoIf the breach contains personal data then you are supposed to report it within 72 hours: https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/ https://ico.org.uk/for-organisations/report-a-breach/persona...
- eterm 1y agoWe were still in the EU when GDPR came along, and we haven't repealed our implementation of it, the Data Protection Act ( 2018 ), which has mandated disclosure in line with GDPR. Even pre-GDPR we had much stronger data protection than most countries with the Data Protection Act ( 1998 ), although I don't remember that having disclosure rules, it did have a lot of things that companies only freaked out about post GDPR and the weight of the EU behind severe penalties.
- testplzignore 1y agoTerrible tech reporting, as is the norm. https://www.bbc.com/news/articles/c8d70d912e6o https://www.bbc.com/news/articles/c8d70d912e6o indicates that the recently announced breach was separate from the one in May (for which the attackers were arrested in July?). I think the one in May leveraged CVE-2025–31324.
- eterm 1y agoThank you, from that article: > A spokesman for the store said that its own system had not been compromised, and that the breach is not connected to a cyber attack in May