LocateBaltimore
No Result
View All Result
No Result
View All Result
LocateBaltimore
No Result
View All Result
Home Technology

How the theft of 40M UK voter register records was entirely preventable

Pauline Wright by Pauline Wright
August 3, 2024
in Technology
0
325
SHARES
2.5k
VIEWS
Share on FacebookShare on Twitter


A cyberattack on the U.Ok. Electoral Commission that resulted in the information breach of voter register records on 40 million folks was entirely preventable had the group used fundamental safety measures, in line with the findings from a damning report by the U.Ok.’s information safety watchdog printed this week.

The report printed by the U.Ok.’s Information Commissioner’s Office on Monday blamed the Electoral Commission, which maintains copies of the U.Ok. register of residents eligible to vote in elections, for a sequence of safety failings that led to the mass theft of voter info starting August 2021.

The Electoral Commission didn’t uncover the compromise of its methods till greater than a 12 months later in October 2022 and took till August 2023 to publicly disclose the year-long information breach.

The Commission mentioned at the time of public disclosure that the hackers broke into servers containing its e mail and stole, amongst different issues, copies of the U.Ok. electoral registers. Those registers retailer info on voters who registered between 2014 and 2022, and embrace names, postal addresses, cellphone numbers and nonpublic voter info.

The U.Ok. authorities later attributed the intrusion to China, with senior officers warning that the stolen information might be used for “large-scale espionage and transnational repression of perceived dissidents and critics in the U.Ok.” China denied involvement in the breach.

The ICO issued its formal rebuke of the Electoral Commission on Monday for violating U.Ok. information safety legal guidelines, including: “If the Electoral Commission had taken fundamental steps to guard its methods, akin to efficient safety patching and password administration, it’s extremely doubtless that this information breach wouldn’t have occurred.” 

For its half, the Electoral Commission conceded in a short assertion following the report’s publication that “adequate protections weren’t in place to stop the cyber-attack on the Commission.” 

Until the ICO’s report, it wasn’t clear precisely what led to the compromise of tens of tens of millions of U.Ok. voters’ info — or what might have been achieved otherwise.

Now we all know that the ICO particularly blamed the Commission for not patching “recognized software program vulnerabilities” in its e mail server, which was the preliminary level of intrusion for the hackers who made off with reams of voter information. The report additionally confirms a element as reported by TechCrunch in 2023 that the Commission’s e mail was a self-hosted Microsoft Exchange server.

In its report, the ICO confirmed that no less than two teams of malicious hackers broke into the Commission’s self-hosted Exchange server throughout 2021 and 2022 utilizing a series of three vulnerabilities collectively known as ProxyShell, which allowed the hackers to interrupt in, take management, and plant malicious code on the server. 

Microsoft launched patches for ProxyShell a number of months earlier in April and May 2021, however the Commission had not put in them.

By August 2021, U.S. cybersecurity company CISA started sounding the alarm that malicious hackers have been actively exploiting ProxyShell, at which level any group that had an efficient safety patching course of in place had already rolled out fixes months in the past and have been already protected. The Electoral Commission was not one of these organizations.

“The Electoral Commission didn’t have an acceptable patching regime in place at the time of the incident,” learn the ICO’s report. “This failing is a fundamental measure.”

Among the different notable safety points found throughout the ICO’s investigation, the Electoral Commission allowed passwords that have been “extremely vulnerable” to have been guessed, and that the Commission confirmed it was “conscious” that components of its infrastructure have been out of date.

ICO deputy commissioner Stephen Bonner mentioned in a press release on the ICO’s report and reprimand: “If the Electoral Commission had taken fundamental steps to guard its methods, akin to efficient safety patching and password administration, it’s extremely doubtless that this information breach wouldn’t have occurred.” 

Why didn’t the ICO nice the Electoral Commission?

An entirely preventable cyberattack that uncovered the private information of 40 million U.Ok. voters may sound like a severe sufficient breach for the Electoral Commission to be penalized with a nice, not only a reprimand. Yet, the ICO has solely issued a public dressing-down for the sloppy safety. 

Public sector our bodies have confronted penalties for breaking information safety guidelines in the previous. But in June 2022 below the prior conservative authorities, the ICO introduced it could trial a revised method to enforcement on public our bodies. 

The regulator mentioned the coverage change meant public authorities can be unlikely to see massive fines imposed for breaches for the subsequent two years, whilst the ICO instructed incidents would nonetheless be totally investigated. But the sector was informed to count on elevated use of reprimands and different enforcement powers, moderately than fines. 

In an open letter explaining the transfer at the time, info commissioner John Edwards wrote: “I’m not satisfied massive fines on their very own are as efficient a deterrent inside the public sector. They don’t affect shareholders or particular person administrators in the identical method as they do in the non-public sector however come straight from the funds for the provision of companies. The affect of a public sector nice can also be usually visited upon the victims of the breach, in the kind of decreased budgets for important companies, not the perpetrators. In impact, folks affected by a breach get punished twice.”

At a look, it’d appear like the Electoral Commission had the success to find its breach inside the ICO’s two-year trial of a softer method to sectoral enforcement.

In live performance with the ICO saying it could check fewer sanctions for public sector information breaches, Edwards mentioned the regulator would undertake a extra proactive workflow of outreach to senior leaders at public authorities to attempt to increase requirements and drive information safety compliance throughout authorities our bodies via a harm-prevention method.

However, when Edwards revealed the plan to check combining softer enforcement with proactive outreach, he conceded it could require effort at each ends, writing: “[W]e can’t do that on our personal. There should be accountability to ship these enhancements on all sides.”

The Electoral Commission breach may due to this fact increase wider questions over the success of the ICO’s trial, together with whether or not public sector authorities have held up their facet of a cut price that was purported to justify the softer enforcement. 

Certainly it doesn’t seem that the Electoral Commission was adequately proactive in assessing breach dangers in the early months of the ICO trial — that’s, earlier than it found the intrusion in October 2022. The ICO’s reprimand dubbing the Commission’s failure to patch recognized software program flaw as a “fundamental measure,” for instance, seems like the definition of an avoidable information breach the regulator had mentioned it needed its public sector coverage shift to purge. 

In this case, nonetheless, the ICO claims it didn’t apply the softer public sector enforcement coverage on this case. 

Responding to questions on why it didn’t impose a penalty on the Electoral Commission, ICO spokeswoman Lucy Milburn informed TechCrunch: “Following a radical investigation, a nice was not thought-about for this case. Despite the quantity of folks impacted, the private information concerned was restricted to primarily names and addresses contained in the Electoral Register. Our investigation didn’t discover any proof that non-public information was misused, or that any direct hurt has been attributable to this breach.”

“The Electoral Commission has now taken the mandatory steps we’d count on to enhance its safety in the aftermath, together with implementing a plan to modernise their infrastructure, in addition to password coverage controls and multi-factor authentication for all customers,” the spokesperson added. 

As the regulator tells it, no nice was issued as a result of no information was misused, or moderately, the ICO didn’t discover any proof of misuse. Merely exposing the info of 40 million voters didn’t meet the ICO’s bar. 

One may marvel how a lot of the regulator’s investigation was targeted on determining how voter info may need been misused? 

Returning to the ICO’s public sector enforcement trial in late June, as the experiment approached the two-year mark, the regulator issued a press release saying it could assessment the coverage earlier than making a call on the future of its sectoral method in the fall. 

Whether the coverage sticks or there’s a shift to fewer reprimands and extra fines for public sector information breaches stays to be seen. Regardless, the Electoral Commission breach case exhibits the ICO is reluctant to sanction the public sector — except exposing folks’s information will be linked to demonstrable hurt. 

It’s not clear how a regulatory method that’s lax on deterrence by design will assist drive up information safety requirements throughout authorities.



Source hyperlink

Tags: 40MChinacyberattackCybersecurityElectoral Commissionmicrosoft exchangepreventablerecordsRegistertheftVoter
Previous Post

Inside the MAGA-fueled 2024 Bitcoin Conference in Nashville, as attendees were divided on Trump's keynote speech, some let down, others calling it historic (Gaby Del Valle/The Verge)

Next Post

Why investors care about climate tech’s green premium

Next Post
Why investors care about climate tech’s green premium

Why investors care about climate tech's green premium

No Result
View All Result

Categories

  • Construction (53)
  • Food (977)
  • Local News (1,995)
  • Local Sports (1,999)
  • Technology (4,000)

Recent.

How to Make Powdered Sugar (Without Cornstarch Option)

How to Make Powdered Sugar (Without Cornstarch Option)

August 25, 2026
Cream of Asparagus Soup with White Wine

Cream of Asparagus Soup with White Wine

August 25, 2026
Easy Whole Wheat Penne With Broccoli (18-Minute Base)

Easy Whole Wheat Penne With Broccoli (18-Minute Base)

August 24, 2026

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

Category

  • Construction (53)
  • Food (977)
  • Local News (1,995)
  • Local Sports (1,999)
  • Technology (4,000)

Tags

2024 Draft 2024 Draft News Air apple Baltimore bridge Chicken Clifton Brown day Derrick Henry draft Easy Experiments Game Gameday Gameday News General Google Heres home Homepage Centerpiece Homepage Latest Headlines iPhone Jackson Key Lamar Lamar Jackson Late For Work Maryland NFL offseason OpenAI Ravens Recipe recipes Ryan Mink Savory season shopping tech TikTok users video Watch week
  • About
  • Home

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • About
  • Home

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.