psydii Posted August 8, 2023 Posted August 8, 2023 Twitter: ...[they] were able to access reference copies of the electoral registers, held by the Commission for research purposes and to enable permissibility checks on political donations. The registers held at the time of the cyber-attack include the name and address of anyone in the UK who registered to vote between 2014 and 2022, as well as the names of those registered as overseas voters. The registers did not include the details of those registered anonymously. The Commission’s email system was also accessible during the attack. https://www.electoralcommission.org.uk/privacy-policy/public-notification-cyber-attack-electoral-commission-systems
DalekSec Posted August 8, 2023 Posted August 8, 2023 I didn't vote for this* *Daleks are not eligible to vote
elsiegee40 Posted August 8, 2023 Posted August 8, 2023 To avoid the wrath of please keep politics out of any discussion on this subject
Brax Posted August 8, 2023 Posted August 8, 2023 Twitter: https://www.electoralcommission.org.uk/privacy-policy/public-notification-cyber-attack-electoral-commission-systems It's unacceptable really that it's taken a whole year to report this to everyone even if the ICO haven't deemed it as "high risk". 1
jthompson Posted August 8, 2023 Posted August 8, 2023 From their notice: "Personal data contained in Electoral Register entries: Name, first name and surname Home address in register entries Date on which a person achieves voting age that year." So for some people, then, that's going to be their date of birth (effectively) in the data.
3s-gtech Posted August 8, 2023 Posted August 8, 2023 Do you think they got access to the DB, or to the admin back end so could overcome any encryption of the data? Was it encrypted at all?
free780 Posted August 9, 2023 Posted August 9, 2023 I wonder if this breach is repeated to the capita beech?
free780 Posted August 9, 2023 Posted August 9, 2023 I wonder if this breach is repeated to the capita beech? *related not repeated
jthompson Posted August 10, 2023 Posted August 10, 2023 More info on this: https://arstechnica.com/security/2023/08/how-an-unpatched-microsoft-exchange-0-day-likely-caused-one-of-the-uks-biggest-hacks-ever/ TLDR: 0-day against an up to date on-prem Exchange. Likely by a Chinese group.
Rob_D Posted August 11, 2023 Posted August 11, 2023 It's unacceptable really that it's taken a whole year to report this to everyone even if the ICO haven't deemed it as "high risk". If it happened in 2021 then it's it 2 years?
Brax Posted August 11, 2023 Posted August 11, 2023 If it happened in 2021 then it's it 2 years? They only discovered it in October 2022. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now