<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Pii on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/pii/</link><description>Recent content in Pii on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 11:13:05 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/pii/index.xml" rel="self" type="application/rss+xml"/><item><title>RAC Data Breach Duo Ordered to Repay £118k</title><link>https://zxcloudsecurity.co.uk/posts/rac-insider-threat-data-breach-car-crash-victims-repay-118k/</link><pubDate>Thu, 04 Jun 2026 11:13:05 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/rac-insider-threat-data-breach-car-crash-victims-repay-118k/</guid><description>Two former RAC staff ordered to repay £118k after selling car crash victims&amp;#39; personal data. A stark reminder of insider threat and GDPR risks.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/cyber-crime/2026/06/04/duo-who-sold-car-crash-victims-data-must-repay-118k/5251075">The Register — Security</a></p>
<hr>
<p>Two former RAC employees who sold personal data belonging to car crash victims to claims management companies have been ordered to repay £118,000 under the Proceeds of Crime Act, following earlier sentences of imprisonment and community service. The pair exploited their privileged access to customer data for financial gain, representing a textbook insider threat and data protection failure. The case underscores the real-world financial and legal consequences of misusing access to sensitive personal data.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review and tighten data access controls for employees handling sensitive personal information — implement least-privilege access, robust audit logging, and anomaly detection to identify unusual data exports or queries, particularly in systems holding customer PII.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/cyber-crime/2026/06/04/duo-who-sold-car-crash-victims-data-must-repay-118k/5251075">Duo who sold car crash victims&rsquo; data must repay £118k</a></p>
]]></content:encoded></item></channel></rss>