News: 1620223272

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

East London council blurts thousands of residents' email addresses in To field blunder

(2021/05/05)


A local authority in East London has committed a classic privacy blunder by emailing what appear to be thousands of residents – while forgetting to use the BCC field and exposing all of the email addresseses to each recipient.

The cockup, which happened on Monday, had locals in the borough of Tower Hamlets receive emails with hundreds of addresses visible.

Register reader Patrick, who was the unlucky recipient of one such message, told us: "The email I received had 400 recipients in the To: field, I assume because Outlook has a limit of 500... Just assuming that I received all the Bs and Cs (and I probably only received a chunk) – then that's ~5,000 email addresses they leaked."

[1]

[2]

[3]

The hapless council followed up with a (correctly BCC'd) email apologising to residents, which stated: "I would like to sincerely apologise on behalf of the Council for the administrative error made in sending this email identifying recipients' individual email addresses. I would like to reassure you that this matter has been reported internally and measures have been taken to avoid such an occurrence in the future."

We have asked the council if it wishes to comment and will update this article if it responds.

"Was a Mailchimp subscription too hard?!" asked Patrick, rhetorically.

[4]

Email privacy blunders are as old as the technology itself. In this day and age of heightened data protection and phishing awareness, such things are taken a bit more seriously than they used to be.

With that said, only a statue could have failed to laugh at a similar blunder from 2019, when a car parts business emailed a bunch of dealers asking them for permission to use their data. Naturally, [5]they did this through the medium of the CC field , turning it into a farce.

Similarly, BT Security managed to email 150 infosec bods who [6]handed over their email addresses at a jobs fair , neatly revealing who each of the potential jobhunters was up against.

[7]

Such screwups can have more serious consequences; an NHS reply-all email chain in 2017 crashed the UK health service's Accenture-run email systems [8]after generating half a billion messages , while in 2016 Chelsea and Westminster NHS Trust was fined £180,000 for [9]repeatedly revealing the email addresses of people using one of its sexual health clinic . ®

Get our [10]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJLBF2MQQldrSTdCeXMCRQAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJLBF2MQQldrSTdCeXMCRQAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJLBF2MQQldrSTdCeXMCRQAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJLBF2MQQldrSTdCeXMCRQAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2019/08/28/gdpr_email_fail/

[6] https://www.theregister.com/2019/11/12/bt_security_cc_bcc_email_fail/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJLBF2MQQldrSTdCeXMCRQAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2017/01/31/nhs_reply_all_email_fail_half_billion_messages/

[9] https://www.theregister.com/2016/05/09/london_nhs_trust_fined_180000_by_ico_over_hiv_newsletter_breach/

[10] https://whitepapers.theregister.com/

Apology accepted

2+2=5

> "I would like to sincerely apologise on behalf of the Council for the administrative error made in sending this email identifying recipients' individual email addresses.

At least they had the decency to call it an administrative error rather than try and claim it was a "computer error".

It's a bit worrying that they seem to have some boiler-plate text ready to cover the situation though. I wonder what else they have to hand: We sincerely apologise for the disruption to dog walkers following the destruction of the dog litter bin in the park when a wayward rocket primary ascent stage crashed down onto it. We will endeavour to re-purpose the remains of the rocket into a new bin as soon as possible, in accordance with our recycling guidelines.

Re: Apology accepted

Anonymous Coward

I think they've just created the boilerplates from an old copy of International Maritime Codes. I can't wait for their version of "XXXV QVVX."

("Have found Lost Continent of Atlantis. High Priest has just won quoits contest." - Good Omens)

Re: Apology accepted

wolfetone

" It's a bit worrying that they seem to have some boiler-plate text ready to cover the situation though. "

So do we use the response under F for Fuck Up? Or T for TITSUP?

Ah, here it is in C. Cock up.

Re: Apology accepted

theblackhand

I admire your optimism that only one level of categorisation is necessary...

RSW

It could only have been better if the email was about keeping your details secure from scammers etc

"Was a Mailchimp subscription too hard?!" asked Patrick, rhetorically.

Mike 137

It has been verified quite a while back by competent lawyers that it's impossible to comply with data protection legislation if you use mailchimp. As usual, the small print in their T&Cs applicable to email recipients is not fully lawful in the EEA and UK.

However, as a matter of course, no organisation ever seems to consider anything except the contractual terms between themselves and the service provider. They never look at the T&Cs imposed on the customers of the organisation by the service provider, and typically they're pretty poor at data protection.

However you don't need a mailchimp subscription. There's been a thing called a distribution list for ages, that allows a mail server to send an individual email to each person on the list.

That's a paddlin'

chivo243

I'm not sure if this falls under a data breach, but a blunder like this would surely get an hour in front of our Data Protection Officer's hair dryer (yes, it's a real position, thanks GDPR!)

Re: That's a paddlin'

Grease Monkey

Yes it is a data breach and the council should have reported it to the ICO as such.

Best way to sort it out: reply to all, Hi all, "have you the same problem?"

Potemkine!

Just for the fun of it ^^

Grease Monkey

I had the misfortune to work in local government until about ten years ago. Even way back before I left we were using tools to send out an individual email when bulk mailing residents. Basically it was the same in house tool as we'd always used to generate snail mail, but mangled to work with email instead of a print run.

Sure it put more load on the mail servers than just sticking a few hundred recipients in the BCC field of a single email, but it didn't have as much opportunity for security cock ups (cocks up?). And it allowed for customised mailing. So you could have the recipient's name in each email "Dear Mr Smith" instead of some generic "Dear Householder" nonsense.

Are your glasses mended with a strip of masking tape right over your nose?
Do you put pennies in the slots in your penny loafers?
Does your bow-tie flash "hey you kid" in red neon at parties?
Do you think pizza before noon is unhealthy?
Do you use the "greasy kid's stuff" to stick down your cowlick?
Do you wear a "nerd-pack" in your shirt pocket to keep the dozen
or so pencils from marking the cloth?
Do you think Mary Jane is somebody's name?
Is illegal fishing something only a daring criminal would do?
Is Batman your hero? Superman? Green Lantern? The Shadow?
Do you think girls who kiss on the first date are loose?

Rate yourself on the nerd-o-matic scale. (1 point for each YES answer)
0-2 -- You are really hip, a real cool cat, a hoopy frood.
3-5 -- There is hope for you yet.
6-7 -- Uh-oh, trouble in River City.
8-10 -- Your immortal soul is in peril.
11+ -- Does suicide seem attractive?