Skip to content
MarketsIndicesCommoditiesFXRates
Finance

P&O Ferries leaks passenger details in text message error

P&O Ferries has suffered a data breach after mistakenly sending the personal details of 432 ferry passengers in a text message update on Monday morning.

P&O Ferries leaks passenger details in text message error

P&O Ferries has suffered a major data breach after mistakenly sending the personal details of 432 passengers travelling from Calais to Dover in a text message.

The blunder occurred on Monday morning during one of the busiest travel days of the year, as thousands of holidaymakers were returning to Britain at the end of the school summer holidays. Customers receiving what appeared to be a routine service update were instead sent a spreadsheet attachment containing confidential passenger data for the sailing.

The attachment included names, customer identification numbers, booking references, email addresses and phone numbers for everyone booked on the 12pm crossing from France to Kent.

The customer service text message stated: "Hello. For your latest P&O Ferries update please view this attachment."

The Channel route between Calais and Dover is the primary ferry link connecting northern France with southeast England, carrying millions of passengers each year across the Strait of Dover. The privacy leak occurred as holidaymakers rushed home before the start of the new school term, a period when cross-Channel transportation networks operate at peak capacity.



Passenger concerns over leaked information

The breach came to light after an affected traveller alerted reporters to the text message. The passenger, a mother-of-three who was returning home to Kent and asked to remain anonymous, expressed deep concern over the privacy failure.

"This is a serious data breach and I am not happy my contact information has been shared with hundreds of passengers," she said.

"Sending out the full passenger list via a text message is an astonishingly reckless misuse of people’s personal details. How on earth have they managed to do this?"

She added: "I am worried about the knock-on effect of my email, phone number and other details now potentially ending up in the hands of scammers."

In response to the incident, P&O Ferries confirmed that it was contacting all affected customers directly to inform them of the error.

"We are aware of an isolated incident this morning in which a link containing certain personal information relating to customers on a single sailing was inadvertently shared with a number of those customers," a spokesman for P&O Ferries said.

"We take the security and confidentiality of personal information seriously and apologise for any inconvenience. We will continue to keep affected customers informed through the appropriate channels as further information becomes available."

P&O Ferries sent an entire boat load of passengers' personal details out by text

Regulatory rules and GDPR obligations

The Information Commissioner's Office, the independent authority responsible for enforcing data privacy regulations in the United Kingdom, stated that P&O Ferries must abide by General Data Protection Regulation rules. Under these statutory standards, the ferry operator is required to assess the severity of the risk and evaluate potential negative consequences for affected individuals.

The regulator noted that potential harms for passengers include emotional distress, physical damage or material harm, such as financial loss, identity theft and discrimination.

"People have the right to expect that organisations will keep their information secure," an ICO spokesman said.

"Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people’s rights and freedoms," the spokesman added. "If an organisation decides that a breach doesn’t need to be reported they should keep their own record of it, and be able to explain why it wasn’t reported if necessary."

Under data protection legislation incorporated into UK law, companies operating in Great Britain face strict statutory duties regarding customer records. Organizations that fail to maintain adequate technical protections or omit mandatory notifications face potential enforcement investigations and regulatory financial penalties.

Wider cyber security concerns in travel

The incident at P&O Ferries follows a major data incident last week targeting Manchester Airports Group, one of the largest airport operators in Britain.

In that incident, hackers accessed personal information belonging to 8.7 million people by targeting infrastructure managing car park bookings, airport lounge access, fast-track pass sales and in-airport Wi-Fi sign-ups across Stansted, Manchester and East Midlands airports.

The customer data accessed in the airport breach included email addresses, telephone numbers, vehicle registration details and postcodes.

A spokesman for Manchester Airports Group stated that the hack was restricted to email addresses for the "vast majority" of affected customers and confirmed that no payment card or banking details were compromised.

Background on P&O Ferries operations

P&O Ferries is owned by Dubai-based logistics company DP World, which purchased the shipping firm in 2019. The company operates passenger and freight ferry routes between Britain and continental Europe, including services to France, the Netherlands and Belgium, alongside crossings connecting mainland Britain to Northern Ireland.

The ferry company operates as an entirely separate business from P&O Cruises, which is owned by cruise operator Carnival Corporation.

P&O Ferries said it will continue updating affected travellers through official customer support channels as its internal investigation continues.

Related

Leave a comment

Your email address will not be published. Required fields are marked *