News: 1616497680

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Thousands of taxpayers' personal details potentially exposed online through councils' debt-chasing texts

(2021/03/23)


Exclusive Bulk SMS messages sent by local councils across the UK contained weblinks leading to pages that freely exposed to the public thousands of taxpayers' names, addresses, and outstanding debts, The Register can reveal.

Text messages sent by Telsolutions Ltd on behalf of a dozen local authorities contained shortlinks to webpages urging council tax defaulters to pay up – and in a dozen cases seen by The Register there was little or no authentication protecting personal data from prying eyes.

[1]

Sent in bulk by around a dozen councils, the messages have reached thousands of defaulters and late payers, although the loophole allowing the data leak has since been closed.

Government statistics

[2]PDF, 16 pages , table 2] show that in England around 3 per cent of council taxes by value were not collected during financial year 2019/20.

[3]

Faced with defaulters, councils have turned to text messages for chasing those who haven't paid on time. As Barnet Council [4]put it : "The Council Tax Service will send SMS text messages, emails and recorded voice messages to you if your Council Tax account falls in to arrears."

[5]

An SMS sent to one of our readers

As part of that service, many councils around the UK use contractors to send those messages. One of those contractors is Telsolutions – and Register reader Jim was very concerned when his council sent him a message with a link in the format textm[.]co/abcde.

Following the link yielded a web page showing his personal data with minimal security – and our reader realised that changing the alphanumeric characters in the URL showed him copies of other people's data. Including, as he told us, information about people who lived in completely separate council areas.

Upon investigating the enumerable URLs, it was discovered that London's Bexley Council, a user of the Telsolutions service, had implemented no authentication at all. Anyone could freely view the full details of an alleged tax defaulter in the borough without proving their identity.

[6]

Bexley Council potentially exposed all of its council taxpayers' details via an SMS service with no authentication at all

To view the information of another taxpayer, all the recipient needed to do was follow the URL from the SMS, alter the alphanumeric characters, and click a button labelled "proceed".

Some councils, such as Walsall in Birmingham, also used disclaimer text with a "proceed" button underneath.

Such click-through "security" protecting personal data from public exposure is meaningless.

Other councils used the Telsolutions system in similar ways. For example, Southampton City Council showed a person's full name and asked for a postcode as verification to view further data.

[7]

Southampton City Council was a user of this SMS service, using easily found postcodes for 'authentication'

The Register pointed out to seven councils using this postcode-based "authentication" system that, for example, using a search engine to look up "Joe Bloggs Southampton" invariably returned address suggestions (complete with postcodes) from sites such as Yell in the top results. A mildly determined criminal could easily use an electoral register lookup service to get a confirmed match.

We counted 14 councils using the system, of which just under a dozen were exposing personal data with few or no meaningful controls. These councils were: Barnet; Bexley; Brighton; Cardiff; Coventry City; Greenwich; Lambeth; Redbridge; Southampton City; and Walsall. Between them, these local authority areas are responsible for more than three million council taxpayers.

Other councils also used the same system, but Telsolutions shortlinks showing their logos returned error strings in place of taxpayers' names and addresses, suggesting that the councils may have ceased using the system.

The common denominator: loophole closed

Telsolutions advertises itself under the slogan "your proactive customer communications partner". Its website also boasts of its status as an approved government G-Cloud supplier and of being on the Crown Commercial Services framework – as well as holding Cyber Essentials certification.

Chief exec Rob Perry-Jones told us: "We take security and all matters of data protection extremely seriously. After identifying a potential vulnerability with one of our systems, we suspended the service immediately and have since further increased security and introduced new measures to prevent malicious intent. Those clients potentially affected have been notified and the service adjusted with new measures."

ESET cyber security specialist Jake Moore commented that though the shortlinked service seemed sensible at first glance, little thought appeared to have been put into properly securing it: "The problems often lie when such processes are innocently created by individuals who fail to test the application with a criminal mindset. It is vital that processes are designed with the help of people trying to [illicitly] hack them or at least an illicit approach is taken into account in order to fully test them."

'We take this very seriously'

Councils responsible for the personal data exposure were hardly apologetic when The Register asked what they had to say for themselves.

A Cardiff Council spokesman said the local authority "takes the processing of personal data and Data Protection legislation extremely seriously, and the concerns raised have been reported to the Data Protection Officer to be investigated, in line with the Council's Data Protection policy and procedure."

A spokesman confirmed that the council had carried out a Data Protection Impact Assessment before using Telsolutions.

Coventry City Council told us: "Telsolutions is used by a number of local authorities and throughout the debt recovery industry. Telsolutions confirm that late in 2020 they discovered an issue with their system which potentially enabled people to access details about council tax payers even if they were not the recipient of such a reminder. In order to access the information a person would need to obtain the postcode for the intended recipient."

The spokesman went on to say "the majority of links sent [were] not being accessed at all", adding that the council "takes very seriously its data protection obligations and works with its numerous suppliers to ensure that our residents’ data is protected."

Capita, responding on behalf of Barnet, Bexley and Lambeth councils (the mega-outsourcer has a contract for collecting taxes on behalf of these local authorities) said: "A technical issue was uncovered with a service that is administered with the support of a specialist supplier. We regard the security of our clients' data with the highest importance and we are working closely with all parties to resolve and investigate this error as quickly as possible."

Southampton City Council said it "takes the protection of our customers' data very seriously and is now investigating this issue."

Walsall Council confirmed it uses Telsolutions and said it "takes its data protection obligations very seriously and works closely with suppliers to ensure that our residents data is protected and immediate action takes place to protect our customers if an issue is identified."

Greenwich Council acknowledged receipt of our request for comment but did not comment.

[8]

Brighton and Southwark Councils failed to respond to requests for comment last week. ®

Get our [9]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YFoeq7M3f@9bU0cZzk1MlgAAAM8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/908532/Collection_Rate_Statistics_Release_update.pdf

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YFoeq7M3f@9bU0cZzk1MlgAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.barnet.gov.uk/council-tax/pay-council-tax/council-tax-sms-text-messaging-email-and-telephone-contact

[5] https://regmedia.co.uk/2021/03/22/original_sms.jpg

[6] https://regmedia.co.uk/2021/03/22/bexley.jpg

[7] https://regmedia.co.uk/2021/03/22/southampton.jpg

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YFoeq7M3f@9bU0cZzk1MlgAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://whitepapers.theregister.com/


Please click the link to read

Anonymous Coward

SMSes prompting the person to click a link to a little-known third-party link shortener! Surely only good things could come from encouraging such behaviour!

Re: Please click the link to read

Anonymous Coward

Happens all the time, management approve "solutions" which encourage poor security behaviour because it's convenient and cheap for them at the time with zero consideration over whether it's right.

The same management will then argue why we need to focus resources on training and raising awareness with staff over fraud etc.

Re: Please click the link to read

Peter Gathercole

I had a dialogue with my water company recently about exactly this.

They sent me a text saying that due to work on the mains, the water from our taps may be disculoured, and provided a short link to a explanatory web page.

When I pointed out to them that there was no way that a recipient could confirm where the text had come from, and that the short link could also not be verified without actually visiting the page, and the page pointed to could be bogus and run by scammers or malware deliverers, they just said that it was common industry practice, and they used a reputable link-shortening service (if there is such a thing).

I referred them back to whatever passes as their cyber security department so they could be educated about the dangers of clicking on uncheckable links, and what the results could be. Funnily enough, I did not get a response from them after this.

Re: Please click the link to read

FlamingDeath

Wait, you think they have a infosec department?

Bwaaahahahaahahahahaaaaa

If they do, it'll be a branch of GCHQ, and they're just there to clear up the mess

Who do you think cleans up the ransomware attacks for these muppets....

An honourable shortener

Diogenes8080

The case for URL shortening services in an era when a URL can be conveniently represented by a short hyperlinked word is indeed marginal. SMS is regrettably one case where it is justifiable, though the [redacted] responsible for the site mentioned in the article could have done better even so. I would be curious to know if misrepresentations were made to the councils in question, or whether IT project staff on the ground failed to read the small print or possibly even the large print written in friendly crayon colours. Capita, as always, remain the clerical omelette.

To judge the worth of a shortening service, see if it offers a convenient reverse service whereby the recipient can input a link and see what it would expand to.

Re: Please click the link to read

Alan Brown

> Funnily enough, I did not get a response from them after this.

You got put in the *plonk* box as a nutter

Now write something explaining the risks in plain english, give it to a journalist and get THEM to ask the question

Alternatively wait 6 weeks and FOI/SDR them on the handling of the exchange, such that they have to explain in detail what they did next

Re: Please click the link to read

MortimerTheCat

I came to the comments to make the same point. I teach people never to click on a link; there are too many phishing messages going around to take a risk. But then you get genuine messages like this one, with an unrecognisable domain undermining my security lessons!

Re: Please click the link to read

Anonymous Coward

Yammer, Teams, Outlook; 365 produces screeds of alert emails which have more triggers than real phishing emails. And there is little MS lets you do to change the configuration or stop them.

How are we supposed to train staff to spot phish when real emails appear less trustworthy?

Re: Please click the link to read

Doctor Syntax

It gets worse.

report@phishing.gov.uk replies to reports with a number of links, mostly to various NCSC sites but also including Action Fraud and usually buried well down the bottom of the reply - too far down to even see without scrolling on my browser. But earlier this month they started including a prominently placed link to a 3rd party survey. Really?

I'd like to think it was really to some site designed to discourage clicking on stray links but more likely they actually thought a 3rd party to a survey didn't look at all suspicious.

Doctor Syntax

"We take security and all matters of data protection extremely seriously. After identifying a potential vulnerability with one of our systems,"

Identifying such a noob vulnerability after the event once it's been pointed out and then describing it as "potential" says a great deal about what they mean by "extremely".

Taking it very seriously

Mike 137

Taking idiotic lack of security very seriously always happens after the fact, not before.

There is actually a statutory duty under the GDPR (to which the UK is still subject via the DPA 2018) to verify that subcontractors have adequate technical and procedural measures in place to protect personal data.

The biggest problem is that effectively no organisation really gives two hoots about personal privacy, so they don't bother to fulfil this duty ( [1]or any other duty under the legislation ). A second problem is that unless a large number of data subjects are directly and seriously affected it's very hard to make any obligation to improve stick, as only the given instance gains attention, not the fundamentally defective sense of responsibility.

[1] http://businessinforisk.co.uk/library/Awful_not_Lawful-final-BiR.pdf

Re: Taking it very seriously

TimMaher

Yeah but, dont forget that Crapita was involved.

Re: Taking it very seriously

a_yank_lurker

Unfortunately it would probably take about dozen public executions of C-suite or equivalent failures to get people's attention. Then they might take it seriously as their hide is on the line.

Doctor Syntax

How many of these councils have reported themselves to the ICO? And have Telesolutions who take all matters of data protection extremely seriously done so?

Halfmad

Assuming they know of the breach most will.

Public sector "has the most breaches" because they are by far (especially Healthcare) far more likely to self-report.

IGotOut

Yup, as there are no consequences for them.

Oh dear, we've been fined £50million. Oh well we'll just cut some services, increase parking fines and costs, slap a few hundred quid on the council tax and close a library.

No biggie.

Doctor Syntax

The most effective way of dealing with public bodies would be to ensure that it ended up as an adverse marking on the annual reports of those responsible. Even better if it could be arranged to show up for several years running.

Anonymous Coward

That's not actually true, ok paying a fine isn't hitting anyone's profit in the public sector but management live in abject terror of the the ICO.

Not enough terror to get them to push down to managers that they need to do their due dilligence properly but quite a bit.

Being on the other side of this, getting large suppliers like Crapita to respond truthfully and openly about any compliance requirements is like trying to make a rock talk. You get ignored, passed around, lied to, deliberately misunderstood, accused of making unreasonable demands, no ones else is bothered why are you!

Middle managers are under pressure to meet tax collection targets, they are not being measured against their GDPR compliance. So if you only have so much time and resource you're going to spend it doing what you are measured on. And so they sign up to crap like this to get on with it.

keith_w

I am surprised the Reg wasn't threatened for 'hacking' peoples personal information!

"We take security and all matters of data protection extremely seriously"

Pascal Monett

That is why we sent out URLs to tens of thousands of people without ever checking that the procedure was secure.

Once the horse had bolted though, we very seriously closed the barn doors.

Hint : stop giving us bullshit about how seriously you take data security when it is absolutely clear that you did not.

I am mildly encouraged...

Jonathan Richards 1

...by the observation that "[T]he majority of links sent [were] not being accessed at all". This tells me that (i) most people dunned by SMS are already well aware that their Council Tax is in arrears, thank you, and (ii) that just maybe people are learning that clicking on the link in response to strident instruction is dangerous .

Re: I am mildly encouraged...

IGotOut

Or the phone numbers were incorrect.

Seriously, we take your data

Chris G

Then we let anyone have access to it because training is hard and expensive to implement properly for our staff.

I have been to in house training sessions at councils where everyone knows everyone, is given a pamphlet or a printout and then have a nice chat for a bit before going back to work tem minutes before knocking off time.

That's how seriously a lot of things are taken.

Proper redaction

AndyFl

Looks like ElReg should get good marks for properly redacting the images in this article rather than just publishing something containing an additional layer with black rectangles. I have to deduct a couple of points for the horrible webp file format :)

The only really secure method of redaction is to mark up the page, print it then take an image of the printout. This guarantees no metadata which might leak sensitive data.

Seriously indifferent

Justin Case

What does taking seriously mean in these cases?

I picture a room full of dour faced bureaucrats proclaiming with sombre earnestness, unleavened by any scintilla of self awareness, that their devotion to the sanctity and protection of personal data is untainted with any degree of levity or inappropriate jocular disregard. When really they mean they don't give a shit, never have and never will. Except of course when it comes to the actions of others.

Muppet.

Aristotles slow and dimwitted horse

"We take security and all matters of data protection extremely seriously"

But obviously not seriously enough to check all of this before actually sending with real world personal data?

Hmm ...

Blofeld's Cat

"... a contract for collecting taxes ..."

I believe contracting out tax collection was also tried in France in the late eighteenth century. It didn't work out terribly well for the people in charge at the time.

It's the one with red Phrygian cap ...

Anonymous Coward

Me, I'm enjoying "innocently created by individuals who fail". Seems a description applicable to so many situations.

Public records

DMcDonnell

The UK is such a strange place.

Here in the USA property records and their attendant

tax bills are considered public records for anyone to see.

Re: Public records

GlenP

The tax bands and hence amount payable is public record here in the UK.

What isn't, and shouldn't, be of public record is that an account is in arrears and by how much (at least until the person is taken to court).

FUCKING COUNCILS!!!!111!!!111oNE

FlamingDeath

Why do we pay councils to then pay other companies to do the thing we paid them to do.

Why don't we just stop paying the council, pool together and just do it our fucking selves

Or would we likely get sent to prison for trying to seek some sanity?

I have yet to see a positive news story about a council, any where.....Do they exist?

Doctor Syntax

On reflection I think this comment I made the other day applies here:

It raises the usual questions about top management:

Do they believe what they say?

Do they believe we'll believe what they say?

Do they think we won't care even when we don't believe what they say?

Do they care whether we care when we don't believe what they say?

None of the alternatives show them up in a good light but I've never been able to determine which is the case given that the only external evidence is that they keep spouting bollocks that only an idiot would believe.

On further reflection I've realised that quotes like this aren't directed at anyone who knows the difference between a shift key, a shift lock key and a control. They're aimed at the execs of the councils involved and any stray councillors who take an interest, the sorts of people who'd be equally likely to spout such bollocks. To adapt the BBC's motto "Management shall spout bollocks unto management".

Anonymous South African Coward

Any Saffers on here remember the time when the City of Johannesburg had the same issue with their billing website? Change the URL slightly, and you get the billing details of somebody else.

IIRC somebody downloaded a ton of bills by running a special program before the CoJ put an end to it by pulling the Ethernet plug on the webserver :)

Seems as if Chitty Councils are the same the world over, want to save a few pennies and end up with unhappy, pissed-off people.

The real man's Bloody Mary:
Ingredients: vodka, tomato juice, Tobasco, Worcestershire
sauce, A-1 steak sauce, ice, salt, pepper, celery.

Fill a large tumbler with vodka.
Throw all the other ingredients away.