Employees Blame Their Employer For Data Theft

A sophisticated cyber attack at a midlands Mercedes dealership led to 'personal data of more than 100 staff being accessed', a data breach specialist law firm has claimed. 

The security breach has now prompted staff to take legal action against their employers.

Legal experts from Hayes Connor are conducting the legal action against Mercedes dealership LSH Auto, which has dealerships in Stockport and Bury, after failing to get any answers from the company about how the data had been breached and what had happened to it.

Staff from the Mercedes dealership LSH Auto, which has sites in Erdington and Solihull, have been affected and this 'security incident' that happened in June 2021.

But today specialist data breach law firm Hayes Connor confirmed the start of the group's legal flight. It includes both current workers at LSH’s eight dealerships and former members of staff. The 106-strong group were first contacted by bosses at the firm by letter more than six months ago which led to serious concerns among those affected. But Hayes Connor said that they "failed to get any answers from the company as to how their data had been breached and what happened to it."

A letter warned staff the business had suffered a "security incident" on June 3, last year, which “may have resulted in unauthorised access to your personal data”. It went on to say that the cyber attack was carried out by "unknown and unauthorised individual(s)."

Experts at Hayes Connor have been working with a growing number of people affected by the breach since then. The firm said the action was a bid to find out exactly how the cyber attack could have happened and what data had been accessed.

It is feared bank details, National Insurance numbers and other personal information could have been compromised in the attack. This, the group’s legal advisers say, has caused them "months of concern as they wait to find out more.

The initial letter caused huge concern amongst those affected," said Christine Sabino, a Legal Director from Hayes Connor. "Being told out of the blue that your data has been breached is worrying enough, but all of those affected still don’t know which data was accessed and what might have happened to it... Whether they still work for this dealership or not, every single one of our clients has a right to know exactly what went wrong here. LSH owes each and every person affected an explanation for this unnecessary distress and should say what they intend to do for them.”

The legal action raises important questions about the responibilty of employers to protect  private, highly personal information and the extent of their liabity when it is exposed or stolen.

Martyn Webb, the managing director at LSH Auto UK, said: “In June 2021, LSH Auto UK was the victim of a sophisticated cyber-attack contained to its UK business. We take the security of our systems and data extremely seriously, and so we immediately took action to protect our systems and engaged forensic specialists to investigate the incident... Our investigations concluded that there was no evidence that any potentially compromised data had been misused and the Information Commissioner’s Office subsequently confirmed that it would not be taking any further action.

“We are sorry this happened and the uncertainty that it caused, we take such matters seriously and have and continue to take all necessary steps to protect against cyber attacks.” Webb said. 

Birmingham  Mail:     Online News UK:    Cyber Security InsidersOlxpraca:     Image: Unsplash

You Might Also Read: 

Blame The Boss For Cyber Attacks:

 

« Hacker Behind Kaseya Ransomware Attack Extradited
Ukraine's 'IT Army' Risks Being Hijacked By Malware »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Global Knowledge Training

Global Knowledge Training

Global Knowledge is a worldwide leader in IT and business training, featuring Cisco, Microsoft, VMware, IBM, security, cloud computing, and project management.

Asavie

Asavie

Asavie provide solutions for Enterprise Mobility Management and secure IoT Connectivity.

SAI360

SAI360

SAI360 (formerly SAI Global) provide products and services for enterprise risk management including Governance, Risk & Compliance and Digital Risk solutions.

Seric Systems

Seric Systems

Seric is a technology business specialising in security, infrastructure and data management.

Entel CyberSecure

Entel CyberSecure

Entel CyberSecure is a portfolio of Cybersecurity solutions and services for the protection, defense, risk management and regulatory compliance of ICT Systems for corporations and Government.

Caulis

Caulis

Caulis FraudAlert is a cyber security solution. It can detect fraud and identity theft based on users’ online behaviour.

GuardRails

GuardRails

GuardRails provides continuous security feedback that empowers developers to find, fix, and prevent vulnerabilities.

IdentityIQ

IdentityIQ

IdentityIQ is a US-based identity theft and credit protection company designed to help users stay on top identity thieves and data breaches.

Octiga

Octiga

Octiga is an office 365 cloud security provider. It offers Office 365 monitoring, incident response and recovery tools.

ABCsolutions

ABCsolutions

ABCsolutions is dedicated to assisting businesses and professionals achieve compliance with federal anti-money laundering regulations in an intelligent and pragmatic way.

BugDazz

BugDazz

BugDazz pentest as a service (PTaaS) platform helps bringing in real-time results, detail coverage, & easy remediation workflows with compliance-ready reports.

Otorio

Otorio

OTORIO delivers industrial cybersecurity and digital risk-management solutions and services. We help our customers to keep their revenue-generating operations resilient, efficient, and safe.

Rootshell Security

Rootshell Security

Rootshell Security is transforming vulnerability management with its vendor-agnostic Prism Platform and industry-leading offensive security assessments.

Data Defenders

Data Defenders

Data Defenders provide information security technology solutions that empower consumers, businesses and governments with safe and secure IT and cybersecurity infrastructures.

Backslash Security

Backslash Security

With Backslash, AppSec teams gain visibility into critical risks in their apps based on reachability and exploitability.

Aberrant

Aberrant

A radically new approach to managing information security. Aberrant is the single pane of glass through which a security program can be viewed.