Security

RAC duo busted for stealing and selling crash victims' data

Roadside assistance biz praised for deploying security monitoring software and reporting workers to cops


Two former workers at roadside assistance provider RAC were this week given suspended sentences after illegally copying and selling tens of thousands of lines of personal data on people involved in accidents.

Debbie Okparavero, 61, of Salford, and Maliha Islam, 51, of Manchester, had worked as customer services specialists at RAC's call center in Stretford until their "unlawful conduct" was spotted by the company and subsequently reported to the Information Commissioner's Office (ICO).

The RAC had installed unspecified security monitoring software, which showed Okparavero accessing and copying "personal information relating to people involved in road traffic accidents." A search of Okparavero's mobile phone revealed the data was then shared with Islam in a WhatsApp chat.

Some 29,500 lines of personal information were exposed, according to the ICO, Britain's data regulator. The chat messages shared between the pair suggested an unknown third party was paying for that data.

The two were handed six-month prison sentences, suspended for 18 months, and ordered to undertake 150 hours of community service at a Minshull Street Crown Court hearing on October 8. Both Okparavero and Islam pleaded guilty to offences under the Computer Misuse Act 1990 and Data Protection Act 2018.

According to the ICO, prosecution costs will be considered at a Proceeds of Crime hearing scheduled for March 5, 2025. Andy Curry, head of ICO investigations, said in a statement: "Accessing people's personal information when there isn't a business need to do so is against the law. To then take steps to profit from other people's misfortune by selling that information is appalling. We will always take action to protect the public from this type of unlawful behavior."

The ICO praised the RAC for its "swift action in bringing this breach to our attention enabling us to ensure justice was served."

The Register asked the RAC for comment but it had nothing to add.

RAC employees have been involved in similar criminal activities before. In 2021, an ex-staffer pleaded guilty to charges of unsanctioned access to computer systems and selling that data to an accident claims management company, while in February last year, the ICO highlighted another former RAC worker involved in a copycat incident. ®

Send us news
21 Comments

US moves ahead with crackdown on data brokers selling to six 'countries of concern'

Biden's Executive Order finally getting its day in the sun, soonish

Worker surveillance must comply with credit reporting rules

US Consumer Financial Protection Bureau demands transparency, accountability from sellers of employee metrics

US lawmakers push DoJ to prosecute tax prep firms for leaking taxpayer data to big tech

TaxSlayer, H&R Block, TaxAct, and Ramsey Solutions accused of sharing info with Meta and Google

Smart TVs are spying on everyone

Regulators know this is a nightmare and have done little to stop it. Privacy advocacy group wants that to change

Cards Against Humanity campaigns to encourage voting, expose personal data abuse

Up to $100 for planning to vote and a public smear – how is this not illegal?

National Public Data files for bankruptcy, admits 'hundreds of millions' potentially affected

One-man-band faces a mountain of lawsuits but has few assets

GSA plows ahead with face matching tech despite its own reliability concerns

A week after saying remote ID verification tech is unreliable, the GSA is expanding access to other agencies

BBC weather glitch shows 13k mph winds in London, 404℃ in Nottingham

We'd know if it were true, and our reporters are just fine

Using iPhone Mirroring at work? You might have just overshared to your boss

What does IT glimpse but a dating app on your wee little screen

Embattled users worn down by privacy options? Let them eat code

Struggle ye not with cookies, lest ye become a cookie monster

Brits hate how big tech handles their data, but can't be bothered to do much about it

Managing the endless stream of cookie banners leaves little energy for anything else

Harvard duo hacks Meta Ray-Bans to dox strangers on sight in seconds

'You can build this in a few days – even as a very naïve developer'