Barclays Bank Breach Exposes 27,000 Customers’ Personal Data

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

The Mail on Sunday reports that an anonymous whistleblower says up to 27,000 confidential customer files have been stolen from Barclays Bank and sold to rogue traders (h/t Infosecurity).

“This is the worst [leak] I’ve come across by far,” the former commodity broker told the Mail. “But this illegal trade is going on all the time in the City. I want to go public to stop it getting bigger.”

According to the newspaper, each file contains about 20 pages of information on customers who had sought financial advice from Barclays.

The whistleblower said he learned of the files when his boss asked him to sell them to other traders. “The data is a gold mine for traders because it is so incredibly detailed,” he said. “It gets them inside the customer’s head.”

In a statement, Barclays said, “We are grateful to the Mail on Sunday for bringing this to our attention and we contacted the Information Commission and other regulators on Friday as soon we were made aware. Our initial investigations suggest this is isolated to customers linked to our Barclays Financial Planning business which we ceased operating as a service in 2011. Based on what we have seen, this appears to be data from 2008 or earlier.”

“We would like to reassure all of our customers that we have taken every practical measure to ensure that personal and financial details remain as safe and secure as possible,” the bank added.

Jeff Goldman Avatar

Subscribe to Cybersecurity Insider

Strengthen your organization’s IT security defenses by keeping abreast of the latest cybersecurity news, solutions, and best practices.

This field is required This field is required

Get the free Cybersecurity newsletter

Strengthen your organization’s IT security defenses with the latest news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday

This field is required This field is required