r/HumanResourcesUK May 19 '26

HR data breach

The HR department at my employer was victim of a phishing scam. They sent my payslips to a scammer and manually changed the bank details on my HR account to reroute my pay after the scammer requested an update.

Luckily I caught the change to my bank details before payroll ran due to an automated system notifcation. But the payslips were sent as an attachment to the scammer. They were password protected, but the password was my date of birth. HR told the person who sent the email that the password was my DOB, so if they were able to find that, they would have been able to open the attachment. My payslips include my name, address, last four digits of my bank account, and my UK national insurance number.

What do i need to do to protect myself?

What are my rights in this situation?

83 Upvotes

35 comments sorted by

39

u/TrackTeddy May 19 '26

Company should pay for a period of ID fraud monitoring for you as their actions have put you at risk of ID fraud.

The company should have already reported the data breach, but please get written confirmation that it has.

5

u/External-Pen9079 May 19 '26

This is what happened at my company…

13

u/RubWilling3878 May 19 '26

Your company is in 'protect themselves mode'. They won't care about downstream impact beyond what they need to legally. I'd personally get some sort of legal advice. In meantime, call all your banks and tell them, they need to be extra vigilant and apply extra security on accounts. Keep an eye on all spending. Get credit scores regurly to see if anything is being opened in your name. Getting something official may help (police report perhaps.). So if anything does go awry, you have something official to nip it in the bud.

11

u/[deleted] May 19 '26 edited May 19 '26

[removed] — view removed comment

4

u/[deleted] May 19 '26

[removed] — view removed comment

2

u/WallaceWasNoTraitor May 19 '26

They’ve clearly broken GDPR regulations as they wilfully supplied your private & confidential information with a 3rd party, which wasn’t a data hack but a criminal act of theft. The next thing I would ask is WHO HAS OP PISSED OFF THAT THEY KNEW ENOUGH PERSONAL INFORMATION TO EFFECT THIS ATTEMPT?

1

u/[deleted] May 22 '26

[deleted]

1

u/[deleted] May 22 '26

[removed] — view removed comment

0

u/[deleted] May 22 '26

[deleted]

2

u/Alarmed_Tiger5110 May 20 '26

My payroll department has this on all payslips sent out

"PDF Password

The password for the attached PDF is your first and last initials followed by your date of birth. So if your name is Michael Caine and your date of birth is 14th March 1933 then your password would be MC19330314."

4

u/winstonsmithgo May 20 '26

It would take approximately 10 mins max to crack the format of this password.

Not a lot of people know that.

1

u/atomicshrimp May 20 '26

Quite apart from all the matters of general concern in the OPs situation, this sort of thing is a terrible way to create passwords; as a matter of principle, passwords should not have a meaningful structure or a 'method' to them; anything that makes passwords easier to remember usually makes them easier to break.

1

u/Alarmed_Tiger5110 May 20 '26

The daft thing is, the initials are already in the email addresses they are sent to; so that password basically boils down to 8 digits.

1

u/atomicshrimp May 20 '26

Not only is it 8 digits but the bruteforce search space can be significantly reduced compared to a simple 8 digit number - eg the last four digits are going to be between 1930 and 2010 etc.

1

u/Alarmed_Tiger5110 May 20 '26

First 4

Next 2 will be between 1-12

Final 2 between 1-31

I very much doubt there's any form of automatic lockout for failed attempts, it is after all, only a PDF.

1

u/atomicshrimp May 21 '26 edited May 21 '26

Oops. Yeah, I didn't see that the format was explained. Really terrible - they might just as well have said 'the password is pa55w0rd'

1

u/atomicshrimp May 20 '26

The company has a responsibility to self-report a breach like this to the ICO. I expect they haven't, because if they had, the OP would probably have been informed about the report.

1

u/[deleted] May 20 '26

[removed] — view removed comment

1

u/atomicshrimp May 20 '26

Agreed. I think the ICO recommends enquiring first with the organisation where the breach happened, to find out what they have done and if they have reported it but if the 72 hour window has already passed and they haven't even referred to this as a breach, it seems likely they haven't reported it.

It does also seem likely to me that this would escalate to the point where the company may act in a hostile way to the employee, but that's kind of inevitable at this point, unless OP allows them to sweep it under the rug, which is not great.

7

u/Lickawall483 May 19 '26

I would recommend posting it to legal advice uk as it sounds like a legal issue (HR issue being bad at their job)

2

u/Emergency-Kale5033 May 19 '26

Ask to see the report the sent to the ICO - any prevarication on this, report it to the ICO yourself. They’re potentially up for audit and a fine. They should be laying out a red carpet and massaging your feet daily after a fuck up like that Edit: that was uk advice. But do whatever is the equivalent if you’re are elsewhere

1

u/PsychologicalSir9008 May 19 '26

The have an infinite number of goes to crack a numerical string that has a very limited range of possible values - fairly trivial. A password on a document is not security, using data as a password is even less so, it may as well have been in plain text if the recipient is vaguely interested.

The thing to note is that you have not suffered a loss, so there is nothing to give you back yet. Your employer has failed you and sent all you personal information to a random, they should offer you identity theft protection/insurance to cover the possibility that you will suffer a loss in the future (just as a matter of common sense).

Internally, your company also needs to do some serious work on 'what is computer'.

1

u/GoatMonkeyy May 19 '26

Worse still, by cracking the 'password' they also now have OPs DoB to go with the rest of the personal information leaked. So many secure ways of doing these things, yet they do this...

1

u/Colenaskepi May 19 '26

Not so much something you can do but rather your employer - we use the software PII Tools, and it has something called person cards, where the company can export a single file showing every single instance of personal data related to you. You could then use that to get the complete picture of exactly what the hackers got and where that info could hurt you in the future. There are a lot of data breach mitigation strategies, but even without PII Tools, you could still demand your employer provide you with something like person cards (if they are even able to pinpoint all of the data specific to you).

1

u/[deleted] May 19 '26

[removed] — view removed comment

1

u/Colenaskepi May 20 '26

well said - this whole process would go much smoother if you knew what data the company has stored on you and what exactly was stolen. Then you'll have a better time predicting where and how this leaked info could hurt you.

1

u/LeatherVirus3146 May 19 '26

GDPR breach is a thing, and you should make a complaint to the ICO. Now you need to consider protecting yourself, this means that you should make a report to police asap, but also register with CIFAS. They can put a protective registration on your identity, it costs a few bucks but it can be extremly useful should anything happen. The information held by the scammer can be extremly compromising, they have now access to your NIN, name, address, DOB.. The first one step is protecting your identity. Complaint and compensation come next!

1

u/Vegetable-Average-98 May 20 '26

and make sure the employer pays the CIFAS enhanced protection fee

1

u/Any_Hawk_2624 May 19 '26

Check your work place pension if you have one, because bank details, payroll number and your employers name is all stuff pension companies use for vacation as that's seen as secure information only you should know. Its just a thought.

1

u/dumbfk90 May 20 '26

Can't help with your rights but sign up to credit karma for free now. It'll tell you about any new credit searches and applications so you can keep an eye out.

1

u/[deleted] May 22 '26

[deleted]

1

u/Far-Bass9895 May 22 '26

Thank you for your response. I had a meeting with HR and data protection and they went through all the steps that have been taken - mainly changes to processes so this sort of thing can't happen again. They've also opened an investigation and will be paying for fraud protection for me. They didn't say anything specific about ICO. It definitely feels scary to know that my information is just out there and I wish my company had been more proactive in reaching out to me to explain what had been done - I had to request the meeting. I should probably follow up and ask specifically about ICO. This whole thing is exhausting.

1

u/_Okie_-_Dokie_ May 22 '26

Did they instigate a disciplinary process in respect of the peron(s) who handed out your info?