A Firm That Sells Protection From Nuisance Calls Fined For Nuisance Calls
September 1, 2026Read also: Türkiye fines a global company 1M lira over a data breach; GS Retail fined 12.8B won over a data breach; and more.

A firm that sells protection from nuisance calls fined for nuisance calls
A company that sells call-blocking devices has been fined £190,000 (~€221,000) for making hundreds of thousands of nuisance calls to elderly people.
Elderly Aids Ltd made 758,053 cold calls between May 2024 and February 2025. Many of the people contacted were registered with the Telephone Preference Service (TPS), which is designed to stop unwanted marketing calls.
Around 20 complaints were made to the UK Information Commissioner’s Office (ICO) and the TPS. Some people said the callers were aggressive and misleading and often did not clearly say who they were.
One complaint said an elderly man was persuaded to pay £139 (€162) upfront and £6.99 (€8.16) a month for a call-blocking service. The ICO said the company was “bombarding people with the very nuisance calls it claimed to protect them from.”
During the investigation, Elderly Aids repeatedly failed to provide information requested by the ICO and continued making calls. The company was also accused of trying to remove itself from the Companies House register after learning about the investigation.
The ICO has ordered the company to stop making illegal marketing calls.
Brazil fines TikTok R$153.7M over children’s data protection failures
Brazil’s privacy regulator ANPD has fined TikTok owner ByteDance R$153.7 million (roughly €25.5 million) for failing to properly protect the personal data of children and teenagers.
The regulator said TikTok violated Brazil’s General Data Protection Law (LGPD) by collecting and processing young users’ data without a valid legal basis or adequate safeguards. The watchdog said TikTok violated articles 6 (items VIII and X) and 7 of the legislation. The violations affected both logged-in users and people browsing TikTok without an account.
The investigation looked at two ways users could access TikTok: the “feed without registration,” which did not require an account, and the “feed with registration,” which required users to create a profile.
In both cases, the ANPD found that TikTok processed children’s and adolescents’ personal data without a valid legal basis. The company also did not have effective measures to prevent children from accessing the platform without registration or from registering when they should not have been allowed to do so. The authority also found that TikTok could not provide enough evidence that its technical and organizational measures were effective in protecting minors’ data.
TikTok was ordered to delete data collected in violation of the rules and has agreed to a compliance plan to address the issues and improve its data practices.
On the same note, Meta has agreed to a proposed settlement of up to $18 billion with 52 US state attorneys general over claims that Facebook and Instagram were designed to encourage addictive use among children and teenagers. Under the settlement, Meta is required to introduce stricter rules for users under 18, including daily screen-time limits, nighttime restrictions, stronger parental controls, age verification, and the removal of some features that may negatively affect teens’ well-being. Meta will pay about $18 billion over 10 years, with around $12.7 billion going to participating states. An independent auditor will monitor the company’s compliance.
South Korea fines two HD Hyundai units over 2024 data leak
South Korea’s Personal Information Protection Commission (PIPC) has fined two HD Hyundai Group companies over a data breach that exposed personal information of 9,503 employees and partner company workers.
The PIPC imposed a 73.5 million (~€46,000) won penalty surcharge on HD Hyundai Construction Equipment and a 4.8 million won (~€3,000) fine on HD Korea Shipbuilding & Offshore Engineering.
The breach took place in March 2024 when an unidentified hacker exploited a security weakness related to file upload vulnerabilities in a mobile device management server operated by HD Korea Shipbuilding & Offshore Engineering. The hacker uploaded a malicious web shell and got access to an internal system at HD Construction Equipment.
The leaked information included the names and employee numbers of executives, employees and partner company workers.
The PIPC said the companies failed to put proper security measures in place, including access controls between their systems. The watchdog said unnecessary “business linkage” between the systems allowed the hacker to move from the compromised server to the system holding personal information.
The regulator said the penalties were imposed for violations of South Korea’s personal information protection laws.
Türkiye fines a global company 1M lira for failure to protect personal data
Türkiye’s Personal Data Protection Authority (KVKK) has fined a global industrial company 1 million Turkish lira for failing to properly protect personal data and for reporting a ransomware attack 23 days late.
The attack began after an employee at the company’s US branch opened a downloaded software, which infected a US server with ransomware. The infection then spread to 797 servers across the company’s global network and encrypted multiple files.
The breach affected the personal information of 4,885 employees, customers and suppliers. The data included identity and passport details, addresses, IBANs, phone numbers and blood types.
KVKK says that previous penetration tests have found several security weaknesses in the network, but the company didn’t provide evidence that the issues were addressed. The authority also found outdated systems, weak password policies, wide network access and limited employee cybersecurity awareness.
The company was fined 800,000 lira for failing to meet data security requirements and another 200,000 lira for reporting the breach late. KVKK said the 23-day delay did not meet the requirement to report data breaches “as soon as possible.” It also said the company’s network security weaknesses increased the potential impact of the attack.
GS Retail fined 12.8B won over data breach affecting 1.66M customers
South Korean retail giant GS Retail, which operates GS25 convenience stores, has been fined 12.8 billion won (about €8.1 million) over a personal data breach affecting about 1.66 million customers.
South Korea’s privacy watchdog said that GS Retail must also pay a 3 million-won administrative penalty, take corrective action and publish the results on its website.
The PIPC found that hackers carried out credential-stuffing attacks against the GS SHOP home shopping website from June 2024 to February 2025. Similar attacks targeted the GS25 website from December 26, 2024, to January 4, 2025.
Credential stuffing involves using usernames and passwords stolen elsewhere to try to access other online accounts. The commission said GS Retail had failed to put adequate security measures in place, including proper access controls.
In a separate case, the PIPC fined the National Center for the Rights of the Child 863 million won (about €537,000) and imposed a 22.2 million-won (~€14,800) administrative penalty after the loss of digital records involving adoptees and missing children.
The center lost a CD containing about 1.14 million records and an external hard drive containing 30,000 records. The files included sensitive information such as names, addresses, contact details and resident registration numbers.
The PIPC said the center had failed to properly manage the storage devices, could not determine when they were lost and did not report the breach within the required 72-hour period. It also found a database flaw that exposed personal information belonging to 47 adoptees and prospective adoptive parents.
What’s next:
- Request a free product demo or pricing
- Register for our webinars and product trainings
- Read our Cybercrime Investigations weekly blog
- Follow us on LinkedIn, X, Telegram and WhatsApp
- Subscribe to our Newsletter
- Join our Partner Program