Catastrophic MoD Data Breach Caused By Lack of Training On Excel (independent.co.uk)
- Reference: 0184773092
- News link: https://yro.slashdot.org/story/26/07/30/1748239/catastrophic-mod-data-breach-caused-by-lack-of-training-on-excel
- Source link: https://www.independent.co.uk/news/uk/home-news/afghan-data-breach-superinjunction-defence-report-mod-b3022842.html
> The leak, in February 2022, exposed the details of 18,700 Afghans who said they were in danger from the Taliban because of their links to UK forces and now wanted to escape to Britain. The blunder triggered an unprecedented superinjunction used against the national media, including The Independent, and prompted a secret evacuation program -- the cost of which is still unclear but which likely ran into the billions of pounds. Following the revelation by this outlet and others in July last year of the hidden operation, MPs set up an inquiry to scrutinize what had happened. In their report, the defense selection committee concluded that:
>
> - The data breach could have been prevented if Ministry of Defense (MoD) personnel had received basic Excel training
> - By August 2023, when the department discovered the leak, thousands of people already knew that a significant data incident had taken place
> - The government did not strike "the right balance between operational secrecy and democratic accountability" -- and the superinjunction was in place for too long
> - Secrecy denied affected Afghans the chance to take steps to protect themselves and their families and caused delays to evacuation program
> - Thousands of Afghans eligible to come to Britain are still trapped in Afghanistan with the government failing to explain how they will help get families to safety.
>
> MPs have called on the government to publish periodic reassessments of the risks facing Afghan applicants to UK resettlement schemes, with officials to report findings annually. They also want ministers to publish a clear policy explaining how they will help Afghans who are eligible to come to Britain but who have not yet been evacuated. The defense committee have also called on the MoD to explain who was responsible for data protection risk before the Afghan breach, criticizing the lack of accountability within the civil service.
[1] https://www.independent.co.uk/news/uk/home-news/afghan-data-breach-superinjunction-defence-report-mod-b3022842.html
Really? (Score:5, Insightful)
I doubt that any amount of Excel training would have helped for this specific issue. That mistake could be made by anyone. Once you hide a worksheet it's not obvious it's still attached to your workbook... because it's hidden. It's a mistake waiting to happen.
Re: (Score:2)
It's an insane thing to do with sensitive data. It's a great thing to do with tables the users don't need to access when you're using Excel for something that really should be done with a database application :)
Re: Really? (Score:3)
What's insane is that they had a committee investigate the incident and the best they could come up with in their root cause analysis is that the end user needed more excel training.
Re: (Score:2)
It's crazy-making but not completely crazy since their goal was to scapegoat.
It's still a little crazy, because whose fault is it the user wasn't trained?
Re: (Score:2)
"Needs more Excel training" should not be the answer to any problem.
Re: (Score:2)
The problem is that Excel is entirely the wrong tool for something like that. Using it this way is basically gross negligence.
Re: (Score:2)
> I doubt that any amount of Excel training would have helped for this specific issue. That mistake could be made by anyone. Once you hide a worksheet it's not obvious it's still attached to your workbook... because it's hidden. It's a mistake waiting to happen.
Maybe someone should make a course and include that so people don't make that mistake.
Why did you use Excel? (Score:5, Interesting)
Excel is a spreadsheet software, not a data management privacy system. Why do people grossly misuse spreadsheets? This has nothing to do with basic Excel training, this has nothing to do with spreadsheet training, for the simple reason no one should have used a spreadsheet. Whoever decided that a spreadsheet was the right medium, should be fired, and face legal consequences.
Re: (Score:2)
Name an alternative to a spreadsheet that's simple to use and doesn't require an overworked and usually unenthusiastic IT department to set up?
The issue here isn't that they used a spreadsheet, it's that spreadsheets are still treated as toys despite being the exact opposite.
Re: (Score:2)
> Name an alternative to a spreadsheet that's simple to use and doesn't require an overworked and usually unenthusiastic IT department to set up?
A typical "modern" (as in, recently developed, the only meaning of the word which usually applies to government IT) solution is to pay a contractor way too much to develop a solution. Your IT department is barely involved.
Government software is seemingly always super duper specific to the task at hand with no thought for the future, so then you get to pay more millions (or billions) for a new system or major revisions to the old one in a few years. But at least it doesn't generally have this kind of problem
Re: (Score:2)
I couldn't imagine what a contractor would bill a government to build that system, it would be disgusting. All you really need is a server, locked down like a nuns nasty, Postgres (or another DB, MySQL, MariaDB, MongoDB, etc...), and a frontend that has limited scoped access.
Re: (Score:2)
The problem is in the assumption that IT shouldn't be involved. IT should be the ones running the locked down, and bolted shut database, offering a frontend into it, with limited scoped access. It doesn't matter what spreadsheet you use, spreadsheets are not data management platforms, and when you try to mix them, you usually end up burned.
Re: Why did you use Excel? (Score:1)
You can use spreadsheets for data entry and maybe formatting, but there is no need to send a full spreadsheet outside your org, when you donĂ¢(TM)t want them to edit the data. Simple solution is to print to (or save as) PDF and also enter a password for encryption at that point. Only visible data is included, no formulas that can break (e.g. string functions with locale-dependent characters like date format) and no as trivial to make changes or send to the wrong person, accidentally or otherwise.
Re: (Score:2)
Sure, but it's still unsuitable for data management. Obviously people can do advanced data management in a spreadsheet, they host an Excel championship, but that doesn't mean you should use it as a database.
Re: (Score:2)
> Why do people grossly misuse spreadsheets?
Because they're the most powerful and easy to use, and likely only, data manipulation tool a person with no hint of computing-specific education is likely to run across.
Re: (Score:2)
That's a terrible argument. If you only have a screwdriver in your toolbox, that doesn't make it a good hammer because you don't know the difference. I understand that a "normal" computer user isn't going to have DB skills, and InfoSec knowledge, but when it comes to data management, why is a "normal" user going about that without IT, and other DevOps related specialists, especially considering this is government involved?
MoD should ... (Score:2)
... stick to sinking battleships.
Re: (Score:2)
> ... stick to sinking battleships.
But they are the side with the battleships. :-)
Pointless (Score:2)
Considering Excel encryption/protection has been broken on every version of Excel from day 1, if that is what they are relying on, I think their security consultants may need some training.
Gonna Need Some Proof Chief (Score:2)
Excel's file encryption mechanisms are extremely secure. It relied on 128AES encryption until version 2016 when 256AES became available. Excel encryption is susceptible only to brute force password spraying attacks facilitated by weak passwords.
If you can prove otherwise, we'd love to see it.
P.S. This post refers to encryption not cell/sheet protection.
Or maybe intentional? (Score:2)
Excel sheet for sensitive data?
Re: (Score:2)
> Excel sheet for sensitive data?
I've (apparently) got news for you, governments use excel spreadsheets for sensitive data constantly . For a lot of purposes it is the right tool for the job... doesn't sound like it was this time, to be fair, but that doesn't change the general statement. Spreadsheets are often a great place to do data munging before giving the data a final home. The spreadsheets are not the problem, a policy of sharing spreadsheets without having them verified safe to share is. It's a much better policy for example to prin
Re: Or maybe intentional? (Score:2)
A spreadsheet is as good as the software who handles it.
And Excel doesn't seem to ... excell in security and safety.
Nope! (Score:2)
The issue is that the current Sharepoint/OneDrive/Teams sharing feature is an absolute shit show of unmanageability.
We're getting more an more of these unintentional shares and rather than clamping down on the data, people are just getting acclimatize and accepting it as if there is nothing that can be done about it.
There's always been a trade off between usability/convenience and security. We're currently so far into convenience that security is not even an after thought.
Microsoft ends the universe (Score:3)
Microsoft has made is so that everyone who is not a programmer or database engineer defaults to Excel for creating databases. Then they share those databases by emailing them to people. This is the dumbest way to maintain a database. It's also the least secure.
There are many ways to store and share columnar data and any of them is better than Excel. Governments use Excel for everything, so do businesses. Excel is hot, stinking garbage as is most Microsoft software. Same goes for Oracle. Nobody here needs to be told this though; it's common knowledge among those who have even the most modest technical aptitude.
The error was using a Microsoft product! (Score:2)
I get spreadsheets, powerpoint and word files sent to me all the time.
When will people understand this is insecure. And a very non professional, clueless way to share information.
But then why would they understand that, they are using Microsoft products in the real world.
No it was not (Score:4, Insightful)
> The leak happened when an member of MoD personnel sent an Excel file outside of government. They thought the data sheet had the details of around 150 Afghan applicants in it, when it in fact had a hidden tab with details of over 18,500 others. The breach "could still have been prevented" if MoD personnel had "received basic training" on this, the report concluded.
Sure, that's one way the breach might have been prevented, which is a much better word than "could" here because the worker would still have had to first know look for a hidden tab, and then actually do it. People forget to do things they know how to do all the time.
A better way would be to prevent sending any consequential attachments (bigger than a signature image - or even block those too, as sig images can be sourced from the web) and use a sharing portal which prevents embarrassing accidents like this by stripping out any questionable content and being extremely strict about it.
If you're depending on a single worker to remember and do something to avoid people losing their lives, you have already created a bad process, and people will die for it sooner or later.
Re: (Score:2)
Maybe a second responsible party should examine everything before something is published? This is how it works in many places.
Re: (Score:3)
And it works badly. I have personally recovered data were the document was "reviewed". They just were smart enough to ask an actual expert in addition.
Re: (Score:1)
Yes, it was: The person up the chain who hid the sheet in the first place, thinking it was safe after doing so, could have not done that if they were properly trained on Excel. I see this all the time in companies. People hide sheets or columns with sensitive info then send it out like it's perfectly fine. "I hid it!" yea, not how that works Bob.
Re: No it was not (Score:1)
Attaching xlsx files to email should be prohibited. If they want to share data, they can export to PDF and attach that. If data entry or editing is required or the recipient wants to programmatically read that data, they need a proper solution for file sharing and collaboration.