News: 1632223811

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK Ministry of Defence apologises after Afghan interpreters' personal data exposed in email blunder

(2021/09/21)


The UK's Ministry of Defence has launched an internal investigation after committing the classic CC-instead-of-BCC email error – but with the names and contact details of Afghan interpreters trapped in the Taliban-controlled nation.

The horrendous data breach took place yesterday, with Defence Secretary Ben Wallace promising an immediate investigation, [1]according to the BBC .

Included in the breach were profile pictures associated with some email accounts, according to the state-owned broadcaster. The initial email was followed up by a second message urging people who had received the first one to delete it – a way of drawing close attention to an otherwise routine missive.

[2]

The email was reportedly sent by the British government's Afghan Relocations and Assistance Policy (ARAP) unit, urging the interpreters not to put themselves or their families at risk. The ministry was said to have apologised for the "unacceptable breach."

[3]

[4]

"This mistake could cost the life of interpreters, especially for those who are still in Afghanistan," one source told the Beeb.

Since the US-led military coalition pulled out of Afghanistan at the end of August, there have been distressing scenes in the country as the ruling Taliban impose Islamic Sharia law – while hunting down and punishing those who helped the Western militaries. Some interpreters have reportedly been murdered, with others fearing for their lives and the well-being of their families.

[5]Chips'n'China on the agenda as the Quad – Japan, India, Oz, US – prepares to meet

[6]This is AUKUS for China – US, UK, Australia reveal defence tech-sharing pact

[7]WhatsApp pulls plug on Taliban helpline, shuts down official-looking accounts

[8]Mobile carrier Telenor quits Myanmar, says coup makes doing business its way impossible

Most email blunders come with less lethal consequences. A misconfigured NHS mailserver caused real problems in 2016 when the health service's entire email network ground to a halt [9]following a spate of irate reply-all missives , while BT Security managed something superficially similar to the MoD cockup by [10]CC'ing instead of BCC'ing 150 security bods pondering taking a job with the one-time state-owned monopoly.

Meanwhile, a 2019 cockup by a German company saw [11]a hapless minion repeatedly cc all of the firm's UK customers in a message asking for their consent to process their data under GDPR. Presumably they all said "hell no" after that.

[12]

The human error-induced problem is as old as email itself and is arguably inherent in the design of most mail clients used by loose fingered users.

Jake Moore, cybersecurity specialist at ESET, commented: "Human error can still be one of the biggest causes of a data breach, and this can be difficult to protect from within an organisation due to the innocence behind them.

"Insider threats caused by misjudgement or even owning overriding rights are often difficult to foresee and therefore become a challenge for infosecurity teams. Placing restraints in CC fields, for example, would inevitably cause issues against authentic use but it can be difficult to automate processes which are not predicted. This particular mishap may even be the result of [13]burnout which is just as much of a threat to IT as an illicit threat." ®

Get our [14]Tech Resources



[1] https://www.bbc.co.uk/news/uk-58629592

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YUoBvAD4PDe4HPugaDABGgAAAIw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUoBvAD4PDe4HPugaDABGgAAAIw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUoBvAD4PDe4HPugaDABGgAAAIw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2021/09/21/semiconductors_china_quad/

[6] https://www.theregister.com/2021/09/16/aukus_defence_pact/

[7] https://www.theregister.com/2021/08/18/whatsapp_shuts_down_taliban_helpline/

[8] https://www.theregister.com/2021/07/08/telenor_quits_myanmar/

[9] https://www.theregister.com/2016/11/14/nhs_blames_supplier_accenture_850k_user_reply_all_email/

[10] https://www.theregister.com/2019/11/12/bt_security_cc_bcc_email_fail/

[11] https://www.theregister.com/2019/08/28/gdpr_email_fail/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUoBvAD4PDe4HPugaDABGgAAAIw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2020/07/14/infosec_job_change/

[14] https://whitepapers.theregister.com/



SCP

This bungle is incredible and deplorable. Given the obvious sensitivity of the data how was it not marked with a high classification marking which would have required it be kept off systems with open access to the internet and public email.

Also claiming this to be a cc/bcc cock-up is understating it - the lack of confidentiality in public emails is well established (akin to putting the message on a postcard). Why was this being sent by email in the first place? Presumably the sender also had a UK/MoD address - well that would arouse suspicions.

Several people deserve to be hauled over the coals on this one.

Just A Quick Comment

"Several people deserve to be hauled over the coals on this one."

Yes, but they won't be... Government departments closing ranks and all that...

David 132

Slight correction.

Civil Service departments closing ranks.

Regardless of the colour of the government, it's the Sir Humphreys and their Bernards that make these kind of mistakes. You don't think the Defence Minister du jour personally composed that email, do you?

But yeah. Icon regardless. Could we be any shittier to the Afghans who risked their lives to help us?

Too many blunders

elsergiovolador

There have been too many blunders around this to think it was just another accident.

I saw one commenter saying - if they expose all people who helped, they won't have to be bothered to rescue them and then they can avoid all the headache of resettling and possible upset of local population etc. It will be another "Oh well, apols" and two weeks later media and people will forget about Afghanistan anyway.

At least that's how reality of headline driven politics looks like.

Re: Too many blunders

IGotOut

Two weeks? It'll be lucky to make it to tomorrow.

Re: Too many blunders

WhiteDragon43

@elsergiovolador

Same thought crossed my mind - standard whitewash to be applied - any guilty party should take a holiday in Afghanistan to receive their reward from the new government/Taliban as a thankyou.

Don't worry.

IGotOut

They have the details already thanks to a previous **** up.

https://www.telegraph.co.uk/world-news/2021/08/27/british-embassy-left-details-afghan-staff-taliban-find/

Re: Don't worry.

Mike 137

" They have the details already thanks to a previous **** up. "

I can't find a reference, but there was also a report on the BBC news just prior to the final departure that a list of Afghans seeking to leave for safety reasons was handed (not sure by what national force) to a Taliban checkpoint "so they could let them through".

About that EXTRA 1.9 billion pounds.......

Anonymous Coward

Quote 1: “The Ministry of Defence takes its information and data handling responsibilities very seriously.”, Ben Wallace, September 2021

Link: https://www.theguardian.com/uk-news/2021/sep/20/mod-data-breach-puts-lives-at-risk-for-more-than-250-afghan-interpreters

Quote 2. "Britain to spend 1.9 billion pounds on boosting cyber defenses", Philip Hammond, November 2016

Link: https://www.reuters.com/article/us-britain-cyber-idUSKBN12W39K

Interesting that the Reuters report from 2016 said: "....The new National Cyber Security Strategy will provide funding to develop automatic defenses to help protect British businesses and citizens online..."

Yup.."protect" was the word used. Clearly 1.9 billion EXTRA pounds and a new "cyber security" department to boost the STASI in Cheltenham.........

........hasn't managed to reach the MOD in the intervening four plus years.....perhaps with a little "cyber security email training".

Your tax pound sterling at work!!!

SNAFU after SNAFU

Clausewitz 4.0

5-eyes Intel programs are seriously been questioned these days.

I am not a fan of shooting ducks in a barrel, but some people are.

Ouch

codejunky

Could be funny to do this intentionally with a list of ISIS members you want popping off but we really dont want to be shafting those who help us. I wonder if Americans are regretting their choice last election. Can anyone really imagine this seriously stupid failure under Trump?

Re: Ouch

lglethal

You are aware that Trump signed the agreement for the Americans to leave AND set the leaving date. But apparently he didnt do any sort of planning for actually meeting said date.

Biden was an idiot for sticking with the date, but do not start trying to say that this wouldnt have happened if Trump was in charge. It would have. And it probably would have been an even greater clusterf%&k.

Re: Ouch

Throatwarbler Mangrove

"Can anyone really imagine this seriously stupid failure under Trump?"

Short answer: yes. Long answer: *waves vaguely at 2017-2021*

Re: Ouch

Anonymous Coward

"Can anyone really imagine this seriously stupid failure under Trump?"

How about everyone on this planet? Only blinkered partisan fools would find any positives from the US (& UK) involvement in Afghanistan. From Bush, through Obama and Trump to Biden. Same single failure throughout the whole 20 year debacle.

Re: Ouch

Anonymous Coward

So, ehh, to expound upon Colonel Sam Trautman's teachings - if Afghanistan was Russia's Vietnam, then Afghanistan was the US's Afghanistan. Confusing, for sure.

Re: Ouch

Anonymous Coward

Tool.

wolfetone

Starting to think the Guntrader owners use the same security guys as the MoD.

Egregious numpties

Danny 2

This is appallingly bad. I've worked for some remiss employers, I've made mistakes myself, sometimes as sysadmin in compromised places, and yet nothing this basic would have failed.

The person who did it, and the person who hired them, should face serious criminal charges. The responsible minister should resign in disgrace and without any pension, if the word responsible still means anything after the Falklands War. This is akin to abetting terrorism. This is lives. None of my errors cost lives.

How much can the ICO fine those responsible?

AW-S

Would the calculation be based upon the MoD annual budget?

3% of £44.6 billion will keep the ICO afloat for some time to come. They might recruit some extra staff and deal with a couple of my complaints then.

NOTICE:

-- THE ELEVATORS WILL BE OUT OF ORDER TODAY --

(The nearest working elevator is in the building across the street.)