Desk live·
ForensicPost
Insurance/Insider/File 17-0713

Bupa Employee Copied 547,000 Customer Records and Offered Them on AlphaBay

One of 20 staff with unrestricted access to the international health insurer’s CRM exported bulk reports to a personal email account over nine weeks. Nobody was reading the activity logs. The UK regulator fined the company £175,000.

Constructed geometry · not a chart of case data
JurisdictionUnited KingdomLondonthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetBupa Global
ActorInsider
S. Rosler9 min readConfidence: high3 sources reviewed

Bupa Global said on July 13, 2017, that an employee had copied data on 547,000 international health insurance customers and tried to sell it. The records, covering 108,000 policies, held names, birth dates, nationalities, email addresses, phone numbers and policy details. Medical and payment data were not included, the company said, and the Information Commissioner’s Office later agreed.

The copying ran from Jan. 6 to March 11, 2017. Bupa learned of it in June, when an external partner found the data advertised on AlphaBay, the dark-web marketplace that law enforcement would shut down the following month.

Twenty People Who Could Export Everything

The employee worked in a partnership advisory team in Brighton and was one of 20 users with unrestricted access to SWAN, the customer relationship system. According to the ICO, 1,751 staff had some access to it. The employee generated bulk reports, attached them to emails as spreadsheets and zip files, and sent them to a personal account. The system logged all of it. Nobody looked.

The regulator’s findings were about controls rather than the individual: no routine monitoring of SWAN activity, defects in the logging itself and export permissions far wider than any role needed. The ICO said the failures put 1.5 million records at risk, not only the 547,000 taken.

A Pre-GDPR Penalty

The £175,000 fine, announced Sept. 28, 2018, was issued under the Data Protection Act 1998. The General Data Protection Regulation had taken effect four months earlier, but the conduct predated it, so the old cap applied. Under the new regime the same facts could have drawn a penalty measured in percentage of turnover. Bupa dismissed the employee and reported the matter to the police, the ICO and the Financial Conduct Authority.

Why The File Is Here

The insider breach is the case that outside-in security cannot see. No exploit was used and no perimeter was crossed. A person with a legitimate login did what the login allowed, in volume, for nine weeks, and the only detection came from a marketplace listing. The corpus records the same shape in staff and applicant data elsewhere; here it is the customer base of an insurer, and the data left by email.

How we reported this

Compiled from the ICO’s monetary penalty notice and contemporaneous reporting, listed below. Counts and dates are the regulator’s. The employee is not named here and was not named by the company. Whether a prosecution followed was not established. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Bupa Insurance Services Limited, monetary penalty noticeInformation Commissioner’s Office
  2. Health insurer Bupa fined £175k after staffer tried to sell customer data on dark webThe Register
  3. Bupa employee steals 547,000 customers’ dataITPro
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary