Bupa Global said on July 13, 2017, that an employee had copied data on 547,000 international health insurance customers and tried to sell it. The records, covering 108,000 policies, held names, birth dates, nationalities, email addresses, phone numbers and policy details. Medical and payment data were not included, the company said, and the Information Commissioner’s Office later agreed.
The copying ran from Jan. 6 to March 11, 2017. Bupa learned of it in June, when an external partner found the data advertised on AlphaBay, the dark-web marketplace that law enforcement would shut down the following month.
Twenty People Who Could Export Everything
The employee worked in a partnership advisory team in Brighton and was one of 20 users with unrestricted access to SWAN, the customer relationship system. According to the ICO, 1,751 staff had some access to it. The employee generated bulk reports, attached them to emails as spreadsheets and zip files, and sent them to a personal account. The system logged all of it. Nobody looked.
The regulator’s findings were about controls rather than the individual: no routine monitoring of SWAN activity, defects in the logging itself and export permissions far wider than any role needed. The ICO said the failures put 1.5 million records at risk, not only the 547,000 taken.
A Pre-GDPR Penalty
The £175,000 fine, announced Sept. 28, 2018, was issued under the Data Protection Act 1998. The General Data Protection Regulation had taken effect four months earlier, but the conduct predated it, so the old cap applied. Under the new regime the same facts could have drawn a penalty measured in percentage of turnover. Bupa dismissed the employee and reported the matter to the police, the ICO and the Financial Conduct Authority.
Why The File Is Here
The insider breach is the case that outside-in security cannot see. No exploit was used and no perimeter was crossed. A person with a legitimate login did what the login allowed, in volume, for nine weeks, and the only detection came from a marketplace listing. The corpus records the same shape in staff and applicant data elsewhere; here it is the customer base of an insurer, and the data left by email.
Compiled from the ICO’s monetary penalty notice and contemporaneous reporting, listed below. Counts and dates are the regulator’s. The employee is not named here and was not named by the company. Whether a prosecution followed was not established. Graded high. Corrections: corrections@forensicpost.com.
- Bupa Insurance Services Limited, monetary penalty noticeInformation Commissioner’s Office
- Health insurer Bupa fined £175k after staffer tried to sell customer data on dark webThe Register
- Bupa employee steals 547,000 customers’ dataITPro