logo

Attackers have 16-digit card numbers, expiry dates, but not names. Now org gets £500k fine

ID: 71443493-e73d-545c-93c9-19c65e91aefc

STIX ID: report--71443493-e73d-545c-93c9-19c65e91aefc

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-02-20

Date Updated: 2026-04-26

Author: Connor Jones

...
...

In 2017 DSG Retail (trading as Currys) had malware on 5,390 tills that harvested 5.6 million payment card numbers and personal data for ~14 million people; after legal challenges the Court of Appeal ruled that the payment card data must be treated as personal data under the DPA 1998 and sent the case back to the first-tier tribunal, strengthening the ICO's position.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.