Close Menu
TechBrunchTechBrunch
  • Home
  • AI
  • Apps
  • Crypto
  • Security
  • Startups
  • TechCrunch
  • Venture

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

The court denied requests to suspend awards regarding Apple's App Store payment fees

June 6, 2025

Circle IPOs are giving hope to more startups waiting to be published to more startups

June 5, 2025

Perplexity received 780 million questions last month, the CEO says

June 5, 2025
Facebook X (Twitter) Instagram
TechBrunchTechBrunch
  • Home
  • AI

    OpenAI seeks to extend human lifespans with the help of longevity startups

    January 17, 2025

    Farewell to the $200 million woolly mammoth and TikTok

    January 17, 2025

    Nord Security founder launches Nexos.ai to help enterprises move AI projects from pilot to production

    January 17, 2025

    Data proves it remains difficult for startups to raise capital, even though VCs invested $75 billion in the fourth quarter

    January 16, 2025

    Apple suspends AI notification summaries for news after generating false alerts

    January 16, 2025
  • Apps

    The court denied requests to suspend awards regarding Apple's App Store payment fees

    June 6, 2025

    Perplexity received 780 million questions last month, the CEO says

    June 5, 2025

    Bonfire's new software allows users to build their own social communities free from platform control

    June 5, 2025

    x Test to highlight posts that users with dissent

    June 5, 2025

    Google says the updated Gemini 2.5 Pro AI model is excellent at coding

    June 5, 2025
  • Crypto

    Circle IPOs are giving hope to more startups waiting to be published to more startups

    June 5, 2025

    GameStop bought $500 million in Bitcoin

    May 28, 2025

    Vote for the session you want to watch in 2025

    May 26, 2025

    Save $900 + 90% from 2 tickets to destroy 2025 in the last 24 hours

    May 25, 2025

    Only 3 days left to save up to $900 to destroy the 2025 pass

    May 23, 2025
  • Security

    Humanity unveils custom AI models for US national security customers

    June 5, 2025

    Unlock phone company Cellebrite to acquire mobile testing startup Corellium for $170 million

    June 5, 2025

    Ransomware Gangs claim responsibility for Kettering Health Hack

    June 4, 2025

    Former CTO of CrowdStrike's cyber-rivals and how automation can undermine security for early-stage startups

    June 4, 2025

    Data breaches at newspaper giant Lee Enterprises impact 40,000 people

    June 4, 2025
  • Startups

    7 days left: Founders and VCs save over $300 on all stage passes

    March 24, 2025

    AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

    March 24, 2025

    20 Hottest Open Source Startups of 2024

    March 22, 2025

    Andrill may build a weapons factory in the UK

    March 21, 2025

    Startup Weekly: Wiz bets paid off at M&A Rich Week

    March 21, 2025
  • TechCrunch

    OpenSea takes a long-term view with a focus on UX despite NFT sales remaining low

    February 8, 2024

    AI will save software companies' growth dreams

    February 8, 2024

    B2B and B2C are not about who buys, but how you sell

    February 5, 2024

    It's time for venture capital to break away from fast fashion

    February 3, 2024

    a16z's Chris Dixon believes it's time to focus on blockchain use cases rather than speculation

    February 2, 2024
  • Venture

    Less than 48 hours left until display at TC at all stages

    June 5, 2025

    TC Session: AI will be on sale today at Berkeley

    June 5, 2025

    North America accounts for the majority of AI VC investment despite the harsh political environment

    June 5, 2025

    3 days left: Charge all your locations in stages on TC Expo Floor

    June 4, 2025

    From $5 to Financial Empowerment: Why Stash co-founder Brandon Krieg is a must-see for TechCrunch All Stage 2025

    June 4, 2025
TechBrunchTechBrunch

The theft of 40 million UK voter registration records was completely preventable

TechBrunchBy TechBrunchAugust 3, 20247 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Telegram Email


A cyber attack on the UK's Electoral Commission, which led to the leak of 40 million voter register data, could have been entirely preventable if the commission had taken basic security measures, according to a damning report published this week by the UK's data watchdog.

A report published Monday by the UK's Information Commissioner's Office blamed the Electoral Commission, which keeps a copy of the register of citizens eligible to vote in UK elections, for a series of security failings that led to the mass theft of voter information beginning in August 2021.

The elections commission did not realize the intrusion into its systems until October 2022, more than a year later, and only disclosed the year-long data breach in August 2023.

The committee said at the time that the hackers had broken into a server where emails were stored and stolen a copy of the UK electoral register, among other things. The electoral register holds details of voters who registered between 2014 and 2022, including names, addresses, phone numbers and non-public voter details.

The British government later blamed China for the intrusion, and senior officials warned that the stolen data could be used for “large-scale espionage and international repression against perceived dissidents and critics in the UK.” China denied any involvement in the intrusion.

The ICO formally accused the Electoral Commission on Monday of breaching UK data protection law, adding that “if the Electoral Commission had taken basic steps to protect its systems, such as effective security patching and password management, this data breach is likely to have not occurred.”

Meanwhile, in a brief statement after the report was released, the Election Commission acknowledged that “sufficient safeguards had not been put in place to prevent cyber attacks against the commission.”

Until the ICO report, it was unclear what exactly happened that led to the leak of the details of tens of millions of British voters, or what else could have been done.

It turns out the ICO specifically faulted the committee for failing to patch “known software vulnerabilities” in the email server that was the initial point of entry for hackers who stole large amounts of voter data. The report also corroborates details reported by TechCrunch in 2023 that the committee's emails were on a self-hosted Microsoft Exchange server.

In its report, the ICO confirmed that at least two malicious hacker groups had exploited a chain of three vulnerabilities, collectively known as ProxyShell, to compromise the Commission's self-hosted Exchange servers in 2021 and 2022, allowing hackers to gain access, take control and implant malicious code on the servers.

Microsoft released patches for ProxyShell several months ago, in April and May 2021, but the committee did not install them.

By August 2021, the U.S. cybersecurity agency CISA began issuing warnings that malicious actors were actively exploiting ProxyShell. At that point, organizations that had effective security patching processes in place had already deployed fixes and were protected months earlier. Election Commissions were not among those organizations.

“At the time of the incident, the Electoral Commission did not have an adequate patching regime in place,” the ICO report said. “This deficiency is fundamental.”

Among other notable security issues uncovered during the ICO's investigation was that the Electoral Commission allowed “highly easy-to-guess” passwords, and that the commission “knew” that some of its infrastructure was out of date.

In a statement about the ICO's report and disciplinary action, ICO Deputy Commissioner Stephen Bonner said: “If the Electoral Commission had taken basic steps to secure its systems, such as effective security patching and password management, this data breach is likely to have avoided happening.”

Why didn't the ICO fine the Electoral Commission?

The exposure of the personal details of 40 million UK voters in a completely preventable cyber attack may seem like a breach serious enough to warrant a fine rather than just a reprimand for the Electoral Commission, but the ICO only issued a public scolding for lax security practices.

Public bodies have always faced penalties for breaching data protection rules, but in June 2022, under the previous Conservative government, the ICO announced it would pilot a review of how it enforces these rules against public bodies.

The regulator said the policy change meant that public authorities were unlikely to face huge fines for non-compliance over the next two years, despite the ICO indicating it would continue to thoroughly investigate cases, but the industry was told to prepare for an increase in reprimands and the use of other enforcement powers rather than fines.

In an open letter explaining the move, then Information Commissioner John Edwards wrote: “I do not believe that large fines are effective as a deterrent within the public sector. Fines are paid for directly from service provision budgets, rather than impacting shareholders or individual directors, as is the case in the private sector. The impact of public sector fines, in the form of budget cuts to essential services, often falls on the victims of breaches, not the perpetrators. In effect, those affected by breaches are doubly punished.”

At first glance, it may seem that the Electoral Commission was fortunate to have discovered the breach within the two-year period during which the ICO is trialling a more flexible approach to sectoral enforcement.

Echoing the ICO's announcement that it would reduce sanctions for public sector data breaches, Edwards said the regulator would raise standards through a harm prevention approach and adopt a more proactive workflow to engage senior leaders of public organizations to drive data protection compliance across government agencies.

But as Edwards unveiled his plan for testing, which combines more relaxed enforcement with aggressive outreach, he acknowledged that efforts on both sides are needed, writing:[W]”We can't do this alone. We need accountability to make these improvements on all fronts.”

The Electoral Commission's breach could therefore raise broader questions about the success of ICO trials, including whether public authorities kept their side of the bargain in a deal that would have justified more lenient enforcement.

It certainly doesn't appear that the Electoral Commission was proactive enough in assessing the risk of breaches in the early months of the ICO trial, i.e. before it discovered the intrusion in October 2022. For example, the ICO's reprimand, which the Commission describes as a “basic measure” for failing to fix known software flaws, sounds like the definition of an avoidable data breach that the regulator said it wanted to eliminate in its public sector policy shift.

However, in this case, the ICO claims it failed to apply its more relaxed public sector enforcement policy.

When asked why they didn't impose a fine on the Electoral Commission, ICO spokesperson Lucy Milburn told TechCrunch: “Following a thorough investigation, a fine was not considered in this matter. Although the number of people affected was large, the personal data concerned was primarily limited to names and addresses on the electoral roll. Our investigation found no evidence that personal data was misused or that any direct harm was caused as a result of this breach.”

“The Election Commission has taken necessary steps to improve security after the incident, including implementing an infrastructure modernization plan, password policy management and multi-factor authentication for all users,” the spokesperson added.

The regulator explained that no fine was imposed because the data was not misused, or rather, the ICO found no evidence of misuse: simply releasing the information of 40 million voters does not meet the ICO's criteria.

One might wonder how focused the regulators' investigations were on uncovering how voter information was misused.

The ICO's public sector enforcement experiment resumed in late June, with the experiment approaching its two-year milestone, and the regulator issued a statement saying it would review the policy before making a decision on the future of its sectoral approach in the autumn.

It remains to be seen whether this policy will be maintained or whether there will be a shift towards fewer disciplinary actions and more fines for public sector data breaches. Either way, the Electoral Commission data breach shows that the ICO is reluctant to impose sanctions on the public sector unless leaking people's data will lead to clear harm.

It is unclear how a deliberately unenforceable regulatory approach will help to improve data protection standards across government.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Humanity unveils custom AI models for US national security customers

June 5, 2025

Unlock phone company Cellebrite to acquire mobile testing startup Corellium for $170 million

June 5, 2025

Ransomware Gangs claim responsibility for Kettering Health Hack

June 4, 2025

Former CTO of CrowdStrike's cyber-rivals and how automation can undermine security for early-stage startups

June 4, 2025

Data breaches at newspaper giant Lee Enterprises impact 40,000 people

June 4, 2025

Phone Chipmaker Qualcomm fixes 3 zero-days exploited by hackers

June 3, 2025

Leave A Reply Cancel Reply

Top Reviews
Editors Picks

7 days left: Founders and VCs save over $300 on all stage passes

March 24, 2025

AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

March 24, 2025

20 Hottest Open Source Startups of 2024

March 22, 2025

Andrill may build a weapons factory in the UK

March 21, 2025
About Us
About Us

Welcome to Tech Brunch, your go-to destination for cutting-edge insights, news, and analysis in the fields of Artificial Intelligence (AI), Cryptocurrency, Technology, and Startups. At Tech Brunch, we are passionate about exploring the latest trends, innovations, and developments shaping the future of these dynamic industries.

Our Picks

The court denied requests to suspend awards regarding Apple's App Store payment fees

June 6, 2025

Circle IPOs are giving hope to more startups waiting to be published to more startups

June 5, 2025

Perplexity received 780 million questions last month, the CEO says

June 5, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

© 2025 TechBrunch. Designed by TechBrunch.
  • Home
  • About Tech Brunch
  • Advertise with Tech Brunch
  • Contact us
  • DMCA Notice
  • Privacy Policy
  • Terms of Use

Type above and press Enter to search. Press Esc to cancel.