Back to all lessons
Awareness Lessons
3 months ago

Polish Accounting Firm Fined for Email Breach Due to Absent Risk Assessments and Weak Access Controls

An accounting and tax consulting firm in Poland suffered a data breach when an employee's email account was accessed without authorization, exposing sensitive personal data of clients, their employees, and minors. The root failure was twofold: the company lacked adequate access controls to prevent unauthorized account access, and it had never conducted formal risk assessments or tested its security measures before the incident occurred. Poland's UODO ruled that the mere unauthorized access constituted a reportable data breach, reinforcing that organizations cannot wait for confirmed data exfiltration to act. This case highlights that professional services firms handling highly sensitive financial and personal data carry an elevated duty of care under GDPR, and that untested, undocumented security postures leave organizations legally and operationally exposed.

Tactical Insight

Immediate actions

  • Enable multi-factor authentication (MFA) on all employee email accounts, especially those handling sensitive client data.
  • Audit all email accounts for suspicious login activity and revoke any unrecognized active sessions immediately.
  • Notify affected data subjects and relevant supervisory authorities within GDPR-mandated timeframes.

Long-term improvements

  • Conduct and document formal GDPR Article 32 risk assessments for all data processing activities on a regular, scheduled basis.
  • Implement a least-privilege access policy ensuring employees can only access data necessary for their specific role.
  • Establish a written information security policy that includes documented technical and organizational measures for protecting personal data.

Detection & testing measures

  • Deploy email security monitoring with alerts for anomalous login locations, times, or failed authentication attempts.
  • Schedule periodic penetration testing and security control validation to verify that protective measures function as intended.
  • Maintain audit logs of all access to systems storing personal data and review them on a regular basis.