P&O Ferries accidentally distributed a spreadsheet containing the personal information of 432 passengers via a customer service text message. The error occurred during a 12pm crossing from Calais to Dover on a high-traffic travel day.
The 12pm Calais-to-Dover text message blunder
The breach involved a customer service text message sent to travelers during a busy end-of-school-holiday crossing. As reported by This is Money and the Daily Mail, the message invited passengers to "view this attachment" for a latest update. However, the attachment was a spreadsheet containing sensitive data for the entire group of 432 travelers.
The leaked file included names, customer IDs, booking numbers, email addresses, and phone numbers. This level of exposure occurred during a period of high volume for the ferry service, which is owned by the Dubai-based DP World and operates routes between Britain and mainland Europe.
A Kent mother's warning and the ICO's mandate
The human impact of the error was highlighted by an anonymous passenger—a mother of three traveling to Kent—who expressed deep concern regarding the potential for scammers to exploit the leaked contact details. She described the incident as an "astonishingly reckless misuse" of personal information.
The Information Commissioner's Office (ICO) has noted that P&O Ferries must now assess the severity of the risk to these individuals under General Data Protection Regulation (GDPR) rules. According to the ICO, organizations are required to notify the regulator within 72 hours of discovering a breach that poses a risk to people's rights and freedoms.. the regulator emphasized that people have a right to expect their information to be kept secure.
A pattern of tarvel sector vulnerabilities following the MAG hack
This incident at P&O Ferries follows a massive security failure within the broader UK travel industry. Just last week, the Manchester Airports Group (MAG) revealed that hackers had accessed the personal data of 8.7 million people.
The MAG breach affected users of Stansted, Manchester, and East Midlands airports, compromising data related to car park bookings, lounge access, and airport Wi-Fi sign-ups. While MAG stated that bank details were not compromised, the scale of that incident highlights a growing trend of data vulnerabilities affecting travelers across Europe.
Was the breach limited to a single ferry crossing?
Several critical questions remain regarding the scope of the P&O Ferries error .. It is currently unknown whether this mistake was isolated to the 12pm Calais-to-Dover crossing or if other ferry routes operated by the company were affected today.
Furthermore, P&O Ferries has not yet provided a formal response to the reports of the breach. It remains to be seen whether the company will identify the technical or human error that allowed a full passenger spreadsheet to be sent as a mass text attachment .
Comments 0