Lush website open to hackers for four months
Cosmetics retailer Lush has narrowly escaped a hefty fine from the Information Commissioner after its website was hacked and customer account and credit card details stolen
The breach of the Data Protection Act and Lush's failure to process card details in accordance with the Payment Card Industry Data Security Standard mean 95 customers became victims of card fraud.
However in order to issue a fine the Information Commissioner's Office (ICO) must be satisfied that certain principles have been breached. Although an extremely serious case, Lush managed to evade a fine because it had taken some action "A monetary penalty was not issued to Lush because we could not show that they ‘failed to take reasonable steps to prevent the contravention," the ICO told us.