← Back to Daily Briefing

The Information Commissioner's Office (ICO) has successfully secured a £355,880.10 confiscation order against Rizwan Manjra, a former motor insurance employee convicted of unauthorized theft of sensitive personal data. Manjra abused legitimate credentials to exfiltrate "car crash" PII, bypassing standard security protocols to exploit highly sensitive customer information for illicit gain. This enforcement action, executed under the Proceeds of Crime Act, marks a significant escalation in the ICO's strategy to strip perpetrators of financial profits derived from data crimes (Databreaches.net).

Technical analysis of the incident reveals systemic failures in internal controls, specifically regarding Identity and Access Management (IAM) and Data Loss Prevention (DLP) efficacy. The perpetrator exploited overly permissive access rights and a lack of granular audit trails to extract massive datasets without triggering anomaly detection alerts (Measured Collective). For CISOs and security architects, this case underscores the critical necessity of moving beyond static permissions. Organizations must implement robust behavioral monitoring and a Zero Trust architecture capable of detecting anomalous access patterns and the unauthorized scale of data movement in real-time to effectively mitigate high-privilege insider threats (Decision Marketing).

Related posts

  1. Malware News — UK: £355,880.10 confiscation order secured following proceeds of crime hearing
  2. Ico
  3. Measuredcollective
  4. Decisionmarketing

LINK COPIED TO CLIPBOARD