Thursday, January 22, 2026
Economy & Markets
5 min read

UK FCA Data Exfiltration Prosecutions Highlight Malicious Insider Threats

A&O Shearman
January 19, 20263 days ago
UK FCA data exfiltration prosecutions: a reminder of malicious insider risks

AI-Generated Summary
Auto-generated

A mobile network operator employee unlawfully sold customer data, which was then used in a £1.5 million crypto investment scam. The employee and an accomplice faced convictions and fines. This case highlights the significant risk of malicious insider data exfiltration for financial services firms, underscoring the need for robust data security measures to prevent fraud.

This is illustrated in 2025's series of FCA criminal convictions related to a boiler room fraud. These are noteworthy for their data protection and exfiltration aspects. Whilst the FCA's releases (here, here and here) are (as is typical) scant on detail, fraud was apparently perpetrated using customer data stolen from a mobile network operator: A mobile network operator's employee sold confidential customer data to a family friend. The employee was convicted and fined for unlawfully obtaining and disclosing personal data contrary to the Data Protection Act 2018 s.170(1). The family friend was convicted and fined for encouragement and assistance. This data was then likely used in a scam involving cold-calling victims to sell fake crypto investments. At least 65 investors were defrauded and lost over £1.5m. Two individuals were convicted and imprisoned for 12 years total for various relevant offences. Financial services firms face similar risks given their substantial stores of sensitive personal data including contact information, evidence of identity and information about financial behaviours. They also have the "deepest pockets" for the FCA to pursue to provide redress. How to mitigate this risk? The FCA's Financial Crime Guide on data security, whilst concentrating on impersonation, nevertheless contains useful pointers on managing insider risk. So does the FCA's Cyber Coordination Group Insights series (here's the 2024 edition). Some key points to consider:

Rate this article

Login to rate this article

Comments

Please login to comment

No comments yet. Be the first to comment!
    FCA Prosecutions: Insider Data Exfiltration Risks