Google admits harvesting passwords
The ICO will be investigating Google after the search giant admitted to taking emails, URLs and passwords during its Street View operation.
 
 
Google could face a hefty fine from the UK's privacy watchdog after the search giant admitted it had captured passwords, emails and URLs when it collected unencrypted Wi-Fi payload data during its Street View operation.
The Information Commissioner's Office (ICO) said earlier this year it appeared no "meaningful" data had been taken by Google.
However, following investigations by various regulators from across the globe, Google has now admitted it had taken emails, URLs and passwords.
"We want to delete this data as soon as possible, and I would like to apologise again for the fact that we collected it in the first place," said Alan Eustace, senior vice president for engineering and research at Google, in a blog post.
"We are mortified by what happened, but confident that these changes to our processes and structure will significantly improve our internal privacy and security practices for the benefit of all our users."
The ICO said it will now be investigating Google again and will consider a monetary fine, which could reach 500,000 - the maximum penalty open to the ICO.
"Whilst the information we saw at the time did not include meaningful personal details that could be linked to an identifiable person, we have continued to liaise with, and await the findings of, the investigations carried out by our international counterparts," an ICO spokesperson said.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We will be making enquires to see whether this information relates to the data inadvertently captured in the UK, before deciding on the necessary course of action, including a consideration of the need to use our enforcement powers."
Rik Ferguson, senior security advisor at Trend Micro, said it was difficult to see what laws Google would have broken, given no third parties appeared to have seen the data.
"It seems it was completely accidental and unintentional and Google did the best they could in terms of surrendering the information as soon as they discovered there was something they needed to surrender and working with every individual European information commissioner," Ferguson told IT PRO.
"Yes they made a mistake but they've been pretty good at putting their hands up and doing the right thing, which is commendable."
As for whether Google should receive a fine from the ICO, Ferguson said "there was no breach."
"It's difficult to see what laws they would have broken."
However, privacy groups continue to press for penalties, including criminal sanctions, against Google. Earlier this year Privacy International said it believed Google had acted with criminal intent in collecting the data.
Tom Brewster is currently an associate editor at Forbes and an award-winning journalist who covers cyber security, surveillance, and privacy. Starting his career at ITPro as a staff writer and working up to a senior staff writer role, Tom has been covering the tech industry for more than ten years and is considered one of the leading journalists in his specialism.
He is a proud alum of the University of Sheffield where he secured an undergraduate degree in English Literature before undertaking a certification from General Assembly in web development.
- 
 Building enduring channel partnerships in a multi-generational IT environment Building enduring channel partnerships in a multi-generational IT environmentIndustry Insights Partners are evolving from sellers to strategic advisors, prioritizing customer outcomes 
- 
 What can AI do to empower those working in the legal sector today, tomorrow, and beyond? What can AI do to empower those working in the legal sector today, tomorrow, and beyond?Supported AI is transforming the legal profession — from streamlining today’s workflows to shaping tomorrow’s strategies. For firms, the choice is clear: embrace trusted AI tools now or risk falling behind in a rapidly evolving landscape 
- 
 Labour calls for investigation into Hancock's use of private email Labour calls for investigation into Hancock's use of private emailNews Reports claim the former health secretary "routinely" breached guidelines by using his personal Gmail for government business 
- 
 Trump resort will not be charged for breaching data laws Trump resort will not be charged for breaching data lawsNews Presidential hopeful's Scottish golf course failed to register under the Data Protection Act for four years 
- 
 Ministry of Justice hit with £140K data breach fine Ministry of Justice hit with £140K data breach fineNews Information Commissioner's Office hits out after prison staff email sensitive information about inmates to several people. 
- 
 ICO sounds alarm over BYOD in light of Royal Veterinary College data loss ICO sounds alarm over BYOD in light of Royal Veterinary College data lossNews Data protection watchdog claims more must be done to lockdown personal devices in the workplace. 
- 
 4G networks, rural broadband and Jimmy Wales: IT Pro's web comment round-up 4G networks, rural broadband and Jimmy Wales: IT Pro's web comment round-upNews Find out what IT Pro readers make of Vodafone's 4G plans, the rural broadband debate and the Government's web porn clamp down. 
- 
 ICO gives schools a lesson in data protection ICO gives schools a lesson in data protectionNews Data protection watchdog publishes good practice guide for schools. 
- 
 Vaizey: Network operators holding up 4G rollout Vaizey: Network operators holding up 4G rolloutNews Communications minister hits out at litigiousness of network operators for holding up 4G deployments. 
- 
 Education bodies caught in data breach gaffes Education bodies caught in data breach gaffesNews Two laptops are stolen with plenty of unprotected data disappearing with them. 
