NHS Digital exposes hundreds of email addresses after BCC blunder copies in entire invite list to 'Let's talk cyber' event
- Reference: 1634729289
- News link: https://www.theregister.co.uk/2021/10/20/bcc_fail_nhs_digital/
- Source link:
The first email sent yesterday morning thanked participants for "registering for NHS Digital's Full Digital Breakfast: Let's talk cyber, scheduled for Thursday 21 October 2021, 8:00-9:00am."
Apparently Neil Bennett, CISO at NHS Digital, and Phil Huggins, National CISO at NHS X, "along with guest speakers, will have a conversation about the ongoing protection and how an increasingly digitised world means we must be super vigilant and cyber secure, where cyber hygiene is essential in protecting patients."
[1]
According to sources caught up in the email chain, NHS Digital were sending the emails in an attempt to change the invite details. The fourth was a cancellation "again with every single person copied in," one healthcare techie told us.
[2]
[3]
"They have subsequently put an email out to a BCC list that just reiterates the meeting is on but does not acknowledge the data breach.
"Oh and it's still doing the rounds as some people have done the usual 'Reply All', which is a frustration to anyone who didn't want their emails sharing or their inboxes clogging."
[4]
The event, which is scheduled for tomorrow morning, is open to anyone who wants to register. It was estimated by people on the email chain that between 100 to 200 email addresses were shared across the attendee list. It included a mix of private individuals and private company addresses.
As one of those registered told us, the irony wasn't lost on them given the breakfast briefing subject matter. "So, not so conscious of security then."
[5]UK Ministry of Defence apologises – again – after another major email blunder in Afghanistan
[6]East London council blurts thousands of residents' email addresses in To field blunder
[7]Brit housing association blabs 3,500 folks' sexual orientation, ethnicity in email blunder
[8]150 infosec bods now know who they're up against thanks to BT Security cc/bcc snafu
[9]Stop replying! pleads NetApp customer stuck in reply-allpocalypse
As email blunders go, this is ranked pretty low down in terms of seriousness – just think of [10]this story , or [11]this one – but it is more than a little embarrassing.
An NHS Digital spokesperson said of the issue: "We take our responsibility to safeguard personal data extremely seriously. This was an invitation to a closed event sent to individuals who had confirmed they wished to attend.
"As soon as we became aware of concerns we took immediate remedial action including reporting the incident for further investigation and deleting the original invitation.
[12]
"We seek to continually improve our processes and will ensure we provide delegates with an alternative means of attending our events in future."
The Reg has also asked the Information Commissioner's Office if anyone has reported the screwup, and it said it hadn't yet received a report. A spokesperson said: "Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people's rights and freedoms." ®
Get our [13]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YXA9PjzdiVHh4vbMGGjbAgAAABc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YXA9PjzdiVHh4vbMGGjbAgAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YXA9PjzdiVHh4vbMGGjbAgAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YXA9PjzdiVHh4vbMGGjbAgAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2021/09/23/afghan_email_fail_ministry_defence/
[6] https://www.theregister.com/2021/05/05/tower_hamlets_email_fail/
[7] https://www.theregister.com/2020/03/25/watford_community_housing_data_breach/
[8] https://www.theregister.com/2019/11/12/bt_security_cc_bcc_email_fail/
[9] https://www.theregister.com/2017/01/27/netapp_creates_reply_allpocalypse/
[10] https://www.theregister.com/2016/05/09/london_nhs_trust_fined_180000_by_ico_over_hiv_newsletter_breach/
[11] https://www.theregister.com/2018/07/18/ico_hands_sexual_abuse_inquiry_200k_fine_for_security_breach/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YXA9PjzdiVHh4vbMGGjbAgAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
Re: "As soon as we became aware of concerns"
Sounds like:
"Sorry, but we didn't can't be expected to realise just how incompetent we are!"
A practice run
... for when they've got everyone's medical info :(
Re: A practice run
Yep. A perfect response to to the govs failed plans to snaffle everyone health data.
If they can't even send a private email, how can we trust them with our data. Even if they have a thousand rules about what can, and cannot be, done with private data, it only takes one idiot in an organisation and all plans are out the window. In this can there are lots of idiots and many are in government.
Re: A practice run
Unfortunately, if you reward idiots, evolution will give you a plethora...
"deleting the original invitation"
Erm...
Do they not know that once sent an email isn't theirs to delete?
Re: "deleting the original invitation"
"...and deleting the original invitation."
One assumes the spokesperson thinks that EVERYONE uses MS Exchange, where emails can be deleted (or recalled) by the sender.
But one would think that not everyone uses MSX so then the sender has no control, as you say.
Re: "deleting the original invitation"
Even then, unless something has changed in the past couple years you can only actually recall an email that goes to the same domain as you are in. Otherwise you just get another email saying they want to recall the email
Re: "deleting the original invitation"
That tends to be the most effective way to get me to read it.
Re: "deleting the original invitation"
And once it's been read it's a bit late to recall it. In fact, reading the response together with the account it's possible that by "delete" they meant the un-BCCed email to cancel.
"We seek to continually improve our processes and will ensure we provide delegates with an alternative means of attending our events in future."
Does that alternative mean spending tax payers money to create a new system? instead of just using BCC.
Contracts are probably being written right now, ripe for usual suspects to hop on.
Alternative means
They probably mean to use Eventbrite, so the latter can abuse invitees' email addressess instead for electronic direct marketing (and profile them as well).
Lol
Stories like these always remind me of the one in El Reg from a number of years ago of the poor girl who accidentally replied to everyone in her office via an instant message as to how much she'd enjoyed giving one of her colleagues (in the same office) - a blowjob.
Re: Lol
So that's why it's called BCC
Re: Blow by Blow Account
Id forgotten this story - life sucks at times.
Re: Lol
Reminds me of the time, a rather evangelical secretary kept sending everyone she had on her mailing list, stories about the good news of getting to know Jesus. One day she received a mail from GOD who reminded her that everyone was entitled to their own beliefs and suggested the office would be more productive if people only received work related mails on the office system. The shock of it all kept her off work for a week and a public reprimand (all be it with a followup private beer from the boss) of the spoofer so she could see the there were no gods involved the sending of emails.
Re: Lol
>no gods involved the sending of emails.
Although sendmail config is believed to be the work of Cthullu
Re: Lol
What about the daemons?
They work really hard, you know.
Lessons will be learned!
And then promptly forgotten.
Re: Lessons will be learned!
And then promptly already forgotten.
We take our responsibility to safeguard personal data extremely seriously
Yeah, I bet you do. I expect you have the full confidence of the Prime Minister too. That's another phrase that means precisely fuck all.
Re: We take our responsibility to safeguard personal data extremely seriously
>That's another phrase that means precisely fuck all.
It means you're going to be fired within a week
Re: We take our responsibility to safeguard personal data extremely seriously
"It means you're going to be fired within a week"
Or that you have too much support in The Party to be got rid of just yet, or that the PM's waiting for an opportune moment to throw you under the bus to save him/her self. (See, e.g., Gavin Williamson, Chris Grayling etc.)
Style it out
"So thank you for all attending this conference, and I'm going to start by asking you a simple question - did you see how we sent your invitation email? Well that's rule number 1, don't do that"
Considering the subject matter of the meeting, one wonders what the employment criteria are for applicants wanting to work at NHS Digital.
Recognising a lap top two out of three times?
I bet they think IT hygeine is dipping a pc into a bucket of Dettol.
Let's talk cyber
Fatima's next job could be in Tesco's
(as she is currently being informed by HR)
Really, how?
Shouldn't there be a limit on how many recipients can be added to the To: field? Better yet, if mass mailing is to be done, do it with a system that only allows the BCCs! Is this a thing? If not, and you develop it, remember you heard it here first!! I'll just have a few of these for compensation!
Yeah but the problem is always the same : as soon as you define rules to automate mailing, some idiot is going to feel that his case is special and he'll go out of his way to work around the rules and send it the way he wants.
You cannot automate against stupidity, stupidity will win every time. You need to educate stupidity.
With a cattle prod, if necessary.
Icon because integrated battery charge.
"As soon as we became aware of concerns"
Apparently, your awareness required four successive blunders.
You're going to have to do a lot better to make us believe your PR bullcrap.