
Nine million EasyJet customer details lost in data breach

In May 2020 hackers obtained the personal details of 9 million Easyjet customers and the credit card details of a further 2,000+.
15.06.2020
Sabrina Goran (sabrina.goran@irwinmitchell.com) comments on a potential group claim against the airline.
A cyber-attack on EasyJet earlier this year has resulted in the exposure of the email addresses and flight details of nine million of its customers, and the credit card details of 2,208 of those customers. EasyJet reportedly notified affected customers by email in May.
The ICO has confirmed it is investigating the breach. The maximum fine the ICO could issue in respect of a serious data breach is €20,000,000 or 4% of the global annual turnover.
The General Data Protection Regulation (GDPR), allows individuals to bring claims for damages for distress in respect of data breaches such as this. Individuals are not required to have suffered any direct financial loss in order to receive compensation in respect of a data breach. Law firm PGMBM has confirmed it has issued a claim form on behalf of the impacted customers and is seeking to recover up to £2,000 per impacted customer.
https://www.cityam.com/easyjet-woes-grow-after-it-is-hit-with-massive-group-action-claim-over-data-breach/
Key Contacts

Related Articles
Expert CommentAI Promised Efficiency; Now It Is Creating Commercial DisputesArtificial intelligence has moved from boardroom discussion to business reality at remarkable speed. Organisations of all sizes are using AI tools to streamline operations, analyse data, assist in decision making, improve customer service and enhance productivity.
Expert CommentPSC Compliance: Why accuracy matters more than everThe UK’s people with significant control (“PSC”) regime was introduced to make corporate ownership more transparent. In simple terms, companies need to understand who ultimately owns or controls them, record that information properly, and ensure that Companies House is kept up to date when things change.The legal frameworkA stronger focus on register integrityWhere the risks tend to ariseHow companies can reduce the riskWhat this means in practice
Expert CommentQuincecare, APP Fraud and the Search for a Remedy: More Questions Than Answers Following Moorwand v HamblinIn October 2024, the Payment Systems Regulator introduced a mandatory reimbursement framework requiring UK payment service providers to compensate victims of authorised push payment fraud.




