Prospect Custodian Trustees Ltd: ICO to investigate Prospect data breach with Guernsey, Jersey and Isle of Man counterparts

Prospect Custodian Trustees Ltd: ICO to investigate Prospect data breach with Guernsey, Jersey and Isle of Man counterparts

Joint Investigation Launched into Prospect Trade Union Cyber Breach Affecting 160,000 Members

A multi-jurisdictional investigation has been initiated by the UK’s Information Commissioner’s Office (ICO) and data protection authorities in Jersey, Guernsey, and the Isle of Man following a cyber incident in June 2025 that compromised the personal data of Prospect Custodian Trustees Ltd (Prospect), a trade union representing over 160,000 members—including scientists, engineers, and tech professionals.

The breach exposed sensitive information, such as financial data, trade union membership details, ethnic origin, sexual orientation, disability status, and religious beliefs. The joint inquiry aims to assess the scope of the exposed data, potential harm to affected individuals, and Prospect’s compliance with data protection obligations, including:

  • Whether adequate technical and organizational safeguards were in place.
  • Whether breach notification requirements were met.
  • Whether appropriate mitigation steps were taken post-incident.

The investigation reflects a coordinated effort to address cross-border cyber threats, with regulators emphasizing the need for collaborative enforcement to uphold data protection standards. John Edwards (UK ICO), Paul Vane (Jersey), Dr. Alexandra Delaney-Bhattacharya (Isle of Man), and Brent Homan (Guernsey) underscored the importance of accountability in handling sensitive personal data, particularly as cyberattacks increasingly target organizations operating across multiple jurisdictions.

Each authority will examine Prospect’s compliance with its respective data protection laws. No further details will be released while the investigation is ongoing.

Source: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/12/ico-to-investigate-prospect-data-breach-with-guernsey-jersey-and-isle-of-man-counterparts/

Prospect Custodian Trustees Ltd TPRM report: https://www.rankiteo.com/company/prospect

"id": "pro1766059298",
"linkid": "prospect",
"type": "Breach",
"date": "6/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '160,000 members',
                        'industry': 'Professional Associations',
                        'location': 'UK, Jersey, Guernsey, Isle of Man',
                        'name': 'Prospect Custodian Trustees Ltd (Prospect)',
                        'size': '160,000 members',
                        'type': 'Trade Union'}],
 'data_breach': {'number_of_records_exposed': '160,000',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personal information',
                                              'Financial data',
                                              'Sensitive data (trade union '
                                              'membership, ethnic origin, '
                                              'sexual orientation, disability, '
                                              'religious belief)']},
 'date_detected': '2025-06',
 'description': 'A joint investigation has been launched by the Information '
                'Commissioner’s Office and the Data Protection authorities of '
                'Jersey, Guernsey, and Isle of Man into the cyber incident '
                'that compromised data of the trade union Prospect Custodian '
                'Trustees Ltd (Prospect) in June 2025. The breach exposed '
                'members’ personal information including financial data and '
                'sensitive data such as trade union membership, ethnic origin, '
                'sexual orientation, disability, and religious belief.',
 'impact': {'data_compromised': 'Personal information including financial '
                                'data, trade union membership, ethnic origin, '
                                'sexual orientation, disability, and religious '
                                'belief',
            'identity_theft_risk': 'High',
            'payment_information_risk': 'High'},
 'investigation_status': 'Ongoing',
 'references': [{'source': 'Information Commissioner’s Office (ICO)'},
                {'source': 'Jersey Information Commissioner'},
                {'source': 'Isle of Man Information Commissioner'},
                {'source': 'ODPA Guernsey'}],
 'regulatory_compliance': {'regulations_violated': ['UK GDPR',
                                                    'Jersey Data Protection '
                                                    'Law',
                                                    'Guernsey Data Protection '
                                                    'Law',
                                                    'Isle of Man Data '
                                                    'Protection Law'],
                           'regulatory_notifications': 'Yes'},
 'stakeholder_advisories': 'Joint investigation by UK ICO, Jersey, Guernsey, '
                           'and Isle of Man Data Protection authorities.',
 'title': 'Cyber Incident at Prospect Custodian Trustees Ltd',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.