P&O Ferries Reports Data Breach Affecting Calais-Dover Passengers
P&O Ferries has disclosed a data breach involving the unintended sharing of passengers' personal information during a sailing on the Calais-Dover route. The incident occurred on the morning of Monday, 31 August 2026, when a link containing customer data was "inadvertently" sent to multiple passengers on the same vessel.
The company described the breach as an "isolated incident" and confirmed it is directly contacting affected customers to address the issue. A spokesperson apologized for the inconvenience and stated that P&O Ferries takes data security seriously, pledging to keep impacted individuals informed as more details emerge.
The UK Information Commissioner’s Office (ICO) confirmed that P&O Ferries reported the breach, which is now under assessment. Under UK data protection laws, organizations must notify the ICO within 72 hours of discovering a breach unless it poses no risk to individuals' rights. The ICO emphasized that organizations failing to report breaches must maintain internal records and justify their decision.
No further details on the scope of the exposed data or the number of affected passengers have been released. The incident highlights ongoing concerns about data security in the travel sector.
Source: https://www.aol.com/articles/ferry-passengers-hit-data-breach-151217000.html
P&O Ferries TPRM report: https://www.rankiteo.com/company/poferries
"id": "pof1788294845",
"linkid": "poferries",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Passengers on the Calais-Dover '
'route',
'industry': 'Maritime Transport',
'location': 'United Kingdom',
'name': 'P&O Ferries',
'type': 'Company'}],
'attack_vector': 'Inadvertent Data Sharing',
'customer_advisories': 'Direct communication with affected passengers',
'data_breach': {'personally_identifiable_information': True,
'sensitivity_of_data': 'Personally identifiable information',
'type_of_data_compromised': 'Personal information'},
'date_detected': '2026-08-31',
'date_publicly_disclosed': '2026-08-31',
'description': 'P&O Ferries has disclosed a data breach involving the '
"unintended sharing of passengers' personal information during "
'a sailing on the Calais-Dover route. The incident occurred '
'when a link containing customer data was inadvertently sent '
'to multiple passengers on the same vessel.',
'impact': {'brand_reputation_impact': 'Potential reputational damage',
'data_compromised': 'Personal information of passengers',
'identity_theft_risk': 'Potential risk'},
'investigation_status': 'Under assessment by ICO',
'references': [{'source': 'P&O Ferries Statement'},
{'source': 'UK Information Commissioner’s Office (ICO)'}],
'regulatory_compliance': {'regulations_violated': 'UK Data Protection Laws',
'regulatory_notifications': 'Reported to UK '
'Information '
'Commissioner’s Office '
'(ICO)'},
'response': {'communication_strategy': 'Apology and updates to affected '
'individuals',
'containment_measures': 'Directly contacting affected customers'},
'title': 'P&O Ferries Data Breach Affecting Calais-Dover Passengers',
'type': 'Data Breach'}