An account takeover report records how an attacker seized a customer login and moved money. Unauthorised access to the account is the offence in Computer Misuse Act 1990 s.1, with s.2 where a further offence is intended. The payment itself is tested against Fraud Act 2006 s.2. anonym.plus removes victim names, logins, and account data on your device.
When this applies
If customer data was exposed, UK GDPR Art. 33 gives you 72 hours to tell the ICO. Art. 34 may require telling the customer too. The Payment Services Regulations 2017 then decide the refund. A security team hardening login defences needs the method, not the victim.
How anonym.plus handles it
- Open the report in anonym.plus on your device.
- The tool flags victim names, logins, and accounts.
- Local OCR reads a scanned incident sheet.
- Turn the name map OFF for true anonymity.
- Replace each identifier with a label.
- Save the clean copy locally.
What you need to provide
- The incident report (PDF, DOCX, or scan).
- An operator (Replace, with the name map off).
- Optional batch for many incidents.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | victim S. Frey → [VICTIM] |
| Identifiers | EMAIL_ADDRESS | s.frey@example.co.uk → [LOGIN] |
| Financial | UK_BANK_NUMBER | acct 8830 → [ACCOUNT] |
| Money | MONEY | £5,100 drained → [AMOUNT] |
| Contact | PHONE_NUMBER | +44 141 555 7711 → [PHONE] |
| Dates | DATE_TIME | breach 04/2026 → [DATE] |
Compliance achieved
- Unauthorised access is the offence in Computer Misuse Act 1990 s.1, and s.2 where more was intended.
- The payment out is tested against Fraud Act 2006 s.2, false representation.
- UK GDPR Art. 33 gives 72 hours to notify the ICO, and Art. 34 may require telling the customer.
- Refunds for an unauthorised transaction run on the Payment Services Regulations 2017.
- DPA 2018 s.171 makes re-identifying the cleaned report an offence, so keep the map off.
Anonymise account takeover reports offline — see plans & start free →
Limitations & cautions
Recital 26 says the data stays personal while anyone can re-identify it. Keep the name map off for analysis. A unique login or device clue in free text can still single out the victim, so review the narrative.
Frequently asked questions
Is the analysis copy truly anonymous?
Only with the name map off and free-text clues checked. Recital 26 sets that bar, and DPA 2018 s.171 makes re-identifying the result an offence.
Do I have 72 hours to report this?
UK GDPR Art. 33 requires notification to the ICO without undue delay and within 72 hours where feasible. Art. 34 adds a duty to tell the customer where the risk to them is high.
Are login emails flagged like names?
Yes. A login email is treated as an identifier and flagged alongside the victim's name.