East London council blurts thousands of residents' email addresses in To field blunder
- Reference: 1620223272
- News link: https://www.theregister.co.uk/2021/05/05/tower_hamlets_email_fail/
- Source link:
The cockup, which happened on Monday, had locals in the borough of Tower Hamlets receive emails with hundreds of addresses visible.
Register reader Patrick, who was the unlucky recipient of one such message, told us: "The email I received had 400 recipients in the To: field, I assume because Outlook has a limit of 500... Just assuming that I received all the Bs and Cs (and I probably only received a chunk) – then that's ~5,000 email addresses they leaked."
[1]
[2]
[3]
The hapless council followed up with a (correctly BCC'd) email apologising to residents, which stated: "I would like to sincerely apologise on behalf of the Council for the administrative error made in sending this email identifying recipients' individual email addresses. I would like to reassure you that this matter has been reported internally and measures have been taken to avoid such an occurrence in the future."
We have asked the council if it wishes to comment and will update this article if it responds.
"Was a Mailchimp subscription too hard?!" asked Patrick, rhetorically.
[4]
Email privacy blunders are as old as the technology itself. In this day and age of heightened data protection and phishing awareness, such things are taken a bit more seriously than they used to be.
With that said, only a statue could have failed to laugh at a similar blunder from 2019, when a car parts business emailed a bunch of dealers asking them for permission to use their data. Naturally, [5]they did this through the medium of the CC field , turning it into a farce.
Similarly, BT Security managed to email 150 infosec bods who [6]handed over their email addresses at a jobs fair , neatly revealing who each of the potential jobhunters was up against.
[7]
Such screwups can have more serious consequences; an NHS reply-all email chain in 2017 crashed the UK health service's Accenture-run email systems [8]after generating half a billion messages , while in 2016 Chelsea and Westminster NHS Trust was fined £180,000 for [9]repeatedly revealing the email addresses of people using one of its sexual health clinic . ®
Get our [10]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJLBF2MQQldrSTdCeXMCRQAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJLBF2MQQldrSTdCeXMCRQAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJLBF2MQQldrSTdCeXMCRQAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJLBF2MQQldrSTdCeXMCRQAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2019/08/28/gdpr_email_fail/
[6] https://www.theregister.com/2019/11/12/bt_security_cc_bcc_email_fail/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJLBF2MQQldrSTdCeXMCRQAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2017/01/31/nhs_reply_all_email_fail_half_billion_messages/
[9] https://www.theregister.com/2016/05/09/london_nhs_trust_fined_180000_by_ico_over_hiv_newsletter_breach/
[10] https://whitepapers.theregister.com/
Re: Apology accepted
I think they've just created the boilerplates from an old copy of International Maritime Codes. I can't wait for their version of "XXXV QVVX."
("Have found Lost Continent of Atlantis. High Priest has just won quoits contest." - Good Omens)
Re: Apology accepted
" It's a bit worrying that they seem to have some boiler-plate text ready to cover the situation though. "
So do we use the response under F for Fuck Up? Or T for TITSUP?
Ah, here it is in C. Cock up.
Re: Apology accepted
I admire your optimism that only one level of categorisation is necessary...
It could only have been better if the email was about keeping your details secure from scammers etc
"Was a Mailchimp subscription too hard?!" asked Patrick, rhetorically.
It has been verified quite a while back by competent lawyers that it's impossible to comply with data protection legislation if you use mailchimp. As usual, the small print in their T&Cs applicable to email recipients is not fully lawful in the EEA and UK.
However, as a matter of course, no organisation ever seems to consider anything except the contractual terms between themselves and the service provider. They never look at the T&Cs imposed on the customers of the organisation by the service provider, and typically they're pretty poor at data protection.
However you don't need a mailchimp subscription. There's been a thing called a distribution list for ages, that allows a mail server to send an individual email to each person on the list.
That's a paddlin'
I'm not sure if this falls under a data breach, but a blunder like this would surely get an hour in front of our Data Protection Officer's hair dryer (yes, it's a real position, thanks GDPR!)
Re: That's a paddlin'
Yes it is a data breach and the council should have reported it to the ICO as such.
Best way to sort it out: reply to all, Hi all, "have you the same problem?"
Just for the fun of it ^^
I had the misfortune to work in local government until about ten years ago. Even way back before I left we were using tools to send out an individual email when bulk mailing residents. Basically it was the same in house tool as we'd always used to generate snail mail, but mangled to work with email instead of a print run.
Sure it put more load on the mail servers than just sticking a few hundred recipients in the BCC field of a single email, but it didn't have as much opportunity for security cock ups (cocks up?). And it allowed for customised mailing. So you could have the recipient's name in each email "Dear Mr Smith" instead of some generic "Dear Householder" nonsense.
Apology accepted
> "I would like to sincerely apologise on behalf of the Council for the administrative error made in sending this email identifying recipients' individual email addresses.
At least they had the decency to call it an administrative error rather than try and claim it was a "computer error".
It's a bit worrying that they seem to have some boiler-plate text ready to cover the situation though. I wonder what else they have to hand: We sincerely apologise for the disruption to dog walkers following the destruction of the dog litter bin in the park when a wayward rocket primary ascent stage crashed down onto it. We will endeavour to re-purpose the remains of the rocket into a new bin as soon as possible, in accordance with our recycling guidelines.