Nine million EasyJet customer details lost in data breach

featured image

In May 2020 hackers obtained the personal details of 9 million Easyjet customers and the credit card details of a further 2,000+.

15.06.2020

Sabrina Goran (sabrina.goran@irwinmitchell.com) comments on a potential group claim against the airline.

A cyber-attack on EasyJet earlier this year has resulted in the exposure of the email addresses and flight details of nine million of its customers, and the credit card details of 2,208 of those customers. EasyJet reportedly notified affected customers by email in May. 

The ICO has confirmed it is investigating the breach. The maximum fine the ICO could issue in respect of a serious data breach is €20,000,000 or 4% of the global annual turnover. 

The General Data Protection Regulation (GDPR), allows individuals to bring claims for damages for distress in respect of data breaches such as this. Individuals are not required to have suffered any direct financial loss in order to receive compensation in respect of a data breach. Law firm PGMBM has confirmed it has issued a claim form on behalf of the impacted customers and is seeking to recover up to £2,000 per impacted customer. 

https://www.cityam.com/easyjet-woes-grow-after-it-is-hit-with-massive-group-action-claim-over-data-breach/

Key Contacts

Related Articles

  • POCA reform in 2026: stronger asset recovery powers, sharper practical risks
    Expert Comment
    POCA reform in 2026: stronger asset recovery powers, sharper practical risks
    When enforcement authorities freeze an account or restrain assets, the impact is immediate.AFOs and restraint orders: earlier intervention, broader impactFunding and access to representationWhy this mattersKey takeaways
  • Licensing authorities face a more transparent and more equality-focused operating environment
    Expert Comment
    Licensing authorities face a more transparent and more equality-focused operating environment
    Licensing authorities are entering a period of notable procedural change. While the reforms come from different sources, their combined effect is clear: licensing decisions will need to be more transparent, better evidenced and more accessible to applicants, licence holders and affected communities.What this means in practiceKey takeaways
  • MI5, Agent X and False Evidence to the Courts: MI5’s non-compliance with their Duty of Candour leads to Contempt of Court
    Expert Comment
    MI5, Agent X and False Evidence to the Courts: MI5’s non-compliance with their Duty of Candour leads to Contempt of Court
    “Neither Confirm No Deny” (“NCND”) is a longstanding policy relied upon by intelligence and law enforcement agencies. The rationale is that confirming or denying the identity of informants, intelligence assets or operational methods may, in itself, damage national security.

Recognised for excellence. Chosen for care.

  • Legal 500 Top Tier Firm UK 202
  • alt tzt
  • Sunday Times Best Places to Work 2025