Diplomats are supposed to be subtle and clever. Australia’s just leaked 1,000 citizens’ email addresses
(2020/10/01)
- Reference: 1601526235
- News link: https://www.theregister.co.uk/2020/10/01/dfat_email_leak/
- Source link:
Australia’s Department of Foreign Affairs and Trade (DFAT) has just exposed personal details of over 1,000 citizens in an email.
Australia has all-but-closed its borders during the COVID-19 pandemic, rationing the number of citizens who can fly into the country each day. That policy means the few airlines still flying sell their business class seats and not many more, leading to people holding cheaper tickets being bumped off flights and big backlogs of citizens trying to get home to mostly-COVID-free Australia.
Some of those bumped from flights have quit jobs and packed up homes in in anticipation of returning home. Others are no longer permitted to work in whichever country they currently inhabit.
In recent weeks this has led to political pain for the government as Australians ask increasingly pointed questions about why they can’t come home at a time of their choosing.
So last week the government increased entry quotas and started an emergency loans scheme for those in dire need.
And when it emailed potential recipients of those loans, it used the “To” field.
DBA locked in police-guarded COVID-19-quarantine hotel for the last week shares his story with The Register [1]READ MORE
Officials tried to recall the mail, but that seldom works and didn’t do so on this occasion either.
A little later DFAT sent another mail in which it said: "We request your assistance in immediately deleting that email from your IT system and refraining from any further forwarding of the email, to protect the privacy of the individuals concerned."
The Department also tweeted an apology of sorts, but it did not always go down well.
Hey [2]@dfat I am the one that’s impacted with your email bungle. But I’m least bothered about that 👍.
One thing that’s bothering me is your lies in the tweet saying you are working as hard as to get us back home. Show us some proofs about your hard work 😓NONE — Manoj Yandapally (@manojyandapally) [3]October 1, 2020
It may be “government agencies doing dumb things with email” week in Australia’s neighborhood, as a similar breach has emerged with New Zealand’s Civil Aviation Authority allegedly making the same mistake when mailing residents who had complained about drone regulations. That breach is detailed in [4]this video . ®
Get our [5]Tech Resources
[1] https://www.theregister.com/2020/05/11/dba_covid_quarantine_experience/
[2] https://twitter.com/dfat?ref_src=twsrc%5Etfw
[3] https://twitter.com/manojyandapally/status/1311478062551232512?ref_src=twsrc%5Etfw
[4] https://www.youtube.com/watch?v=opz-eDY70vM
[5] https://whitepapers.theregister.com/
Australia has all-but-closed its borders during the COVID-19 pandemic, rationing the number of citizens who can fly into the country each day. That policy means the few airlines still flying sell their business class seats and not many more, leading to people holding cheaper tickets being bumped off flights and big backlogs of citizens trying to get home to mostly-COVID-free Australia.
Some of those bumped from flights have quit jobs and packed up homes in in anticipation of returning home. Others are no longer permitted to work in whichever country they currently inhabit.
In recent weeks this has led to political pain for the government as Australians ask increasingly pointed questions about why they can’t come home at a time of their choosing.
So last week the government increased entry quotas and started an emergency loans scheme for those in dire need.
And when it emailed potential recipients of those loans, it used the “To” field.
DBA locked in police-guarded COVID-19-quarantine hotel for the last week shares his story with The Register [1]READ MORE
Officials tried to recall the mail, but that seldom works and didn’t do so on this occasion either.
A little later DFAT sent another mail in which it said: "We request your assistance in immediately deleting that email from your IT system and refraining from any further forwarding of the email, to protect the privacy of the individuals concerned."
The Department also tweeted an apology of sorts, but it did not always go down well.
Hey [2]@dfat I am the one that’s impacted with your email bungle. But I’m least bothered about that 👍.
One thing that’s bothering me is your lies in the tweet saying you are working as hard as to get us back home. Show us some proofs about your hard work 😓NONE — Manoj Yandapally (@manojyandapally) [3]October 1, 2020
It may be “government agencies doing dumb things with email” week in Australia’s neighborhood, as a similar breach has emerged with New Zealand’s Civil Aviation Authority allegedly making the same mistake when mailing residents who had complained about drone regulations. That breach is detailed in [4]this video . ®
Get our [5]Tech Resources
[1] https://www.theregister.com/2020/05/11/dba_covid_quarantine_experience/
[2] https://twitter.com/dfat?ref_src=twsrc%5Etfw
[3] https://twitter.com/manojyandapally/status/1311478062551232512?ref_src=twsrc%5Etfw
[4] https://www.youtube.com/watch?v=opz-eDY70vM
[5] https://whitepapers.theregister.com/
classic problem with emailing groups on MS products
you would imagine that by now the interface/training would have changed to stop this.
With exchange someone knocks up a group for convience and as it shows a single entry on the "to" field so they go ahead like they would for internal message but since it is going out vias SMTP the email has each recipient rather than just the group name on the "to" line.
MS fail due to showing their own dialog rather than a specific one for SMTP where the user could see who is getting what.
Even a question box saying one of more recipients is going to have the full mailing list are you sure? would be enough