News: 1634729289

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

NHS Digital exposes hundreds of email addresses after BCC blunder copies in entire invite list to 'Let's talk cyber' event

(2021/10/20)


NHS Digital has scored a classic Mail All own-goal by dispatching not one, not two, not three, but four emails concerning an infosec breakfast briefing, each time copying the entirety of the invite list in on the messages.

The first email sent yesterday morning thanked participants for "registering for NHS Digital's Full Digital Breakfast: Let's talk cyber, scheduled for Thursday 21 October 2021, 8:00-9:00am."

Apparently Neil Bennett, CISO at NHS Digital, and Phil Huggins, National CISO at NHS X, "along with guest speakers, will have a conversation about the ongoing protection and how an increasingly digitised world means we must be super vigilant and cyber secure, where cyber hygiene is essential in protecting patients."

[1]

According to sources caught up in the email chain, NHS Digital were sending the emails in an attempt to change the invite details. The fourth was a cancellation "again with every single person copied in," one healthcare techie told us.

[2]

[3]

"They have subsequently put an email out to a BCC list that just reiterates the meeting is on but does not acknowledge the data breach.

"Oh and it's still doing the rounds as some people have done the usual 'Reply All', which is a frustration to anyone who didn't want their emails sharing or their inboxes clogging."

[4]

The event, which is scheduled for tomorrow morning, is open to anyone who wants to register. It was estimated by people on the email chain that between 100 to 200 email addresses were shared across the attendee list. It included a mix of private individuals and private company addresses.

As one of those registered told us, the irony wasn't lost on them given the breakfast briefing subject matter. "So, not so conscious of security then."

[5]UK Ministry of Defence apologises – again – after another major email blunder in Afghanistan

[6]East London council blurts thousands of residents' email addresses in To field blunder

[7]Brit housing association blabs 3,500 folks' sexual orientation, ethnicity in email blunder

[8]150 infosec bods now know who they're up against thanks to BT Security cc/bcc snafu

[9]Stop replying! pleads NetApp customer stuck in reply-allpocalypse

As email blunders go, this is ranked pretty low down in terms of seriousness – just think of [10]this story , or [11]this one – but it is more than a little embarrassing.

An NHS Digital spokesperson said of the issue: "We take our responsibility to safeguard personal data extremely seriously. This was an invitation to a closed event sent to individuals who had confirmed they wished to attend.

"As soon as we became aware of concerns we took immediate remedial action including reporting the incident for further investigation and deleting the original invitation.

[12]

"We seek to continually improve our processes and will ensure we provide delegates with an alternative means of attending our events in future."

The Reg has also asked the Information Commissioner's Office if anyone has reported the screwup, and it said it hadn't yet received a report. A spokesperson said: "Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people's rights and freedoms." ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YXA9PjzdiVHh4vbMGGjbAgAAABc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YXA9PjzdiVHh4vbMGGjbAgAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YXA9PjzdiVHh4vbMGGjbAgAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YXA9PjzdiVHh4vbMGGjbAgAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2021/09/23/afghan_email_fail_ministry_defence/

[6] https://www.theregister.com/2021/05/05/tower_hamlets_email_fail/

[7] https://www.theregister.com/2020/03/25/watford_community_housing_data_breach/

[8] https://www.theregister.com/2019/11/12/bt_security_cc_bcc_email_fail/

[9] https://www.theregister.com/2017/01/27/netapp_creates_reply_allpocalypse/

[10] https://www.theregister.com/2016/05/09/london_nhs_trust_fined_180000_by_ico_over_hiv_newsletter_breach/

[11] https://www.theregister.com/2018/07/18/ico_hands_sexual_abuse_inquiry_200k_fine_for_security_breach/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YXA9PjzdiVHh4vbMGGjbAgAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



"As soon as we became aware of concerns"

Pascal Monett

Apparently, your awareness required four successive blunders.

You're going to have to do a lot better to make us believe your PR bullcrap.

Re: "As soon as we became aware of concerns"

ClockworkOwl

Sounds like:

"Sorry, but we didn't can't be expected to realise just how incompetent we are!"

A practice run

Will Godfrey

... for when they've got everyone's medical info :(

Re: A practice run

JassMan

Yep. A perfect response to to the govs failed plans to snaffle everyone health data.

If they can't even send a private email, how can we trust them with our data. Even if they have a thousand rules about what can, and cannot be, done with private data, it only takes one idiot in an organisation and all plans are out the window. In this can there are lots of idiots and many are in government.

Re: A practice run

ClockworkOwl

Unfortunately, if you reward idiots, evolution will give you a plethora...

"deleting the original invitation"

John Robson

Erm...

Do they not know that once sent an email isn't theirs to delete?

Re: "deleting the original invitation"

Timbo

"...and deleting the original invitation."

One assumes the spokesperson thinks that EVERYONE uses MS Exchange, where emails can be deleted (or recalled) by the sender.

But one would think that not everyone uses MSX so then the sender has no control, as you say.

Re: "deleting the original invitation"

Kientha

Even then, unless something has changed in the past couple years you can only actually recall an email that goes to the same domain as you are in. Otherwise you just get another email saying they want to recall the email

Re: "deleting the original invitation"

Gavin Jamie

That tends to be the most effective way to get me to read it.

Re: "deleting the original invitation"

Doctor Syntax

And once it's been read it's a bit late to recall it. In fact, reading the response together with the account it's possible that by "delete" they meant the un-BCCed email to cancel.

adam payne

"We seek to continually improve our processes and will ensure we provide delegates with an alternative means of attending our events in future."

Does that alternative mean spending tax payers money to create a new system? instead of just using BCC.

elsergiovolador

Contracts are probably being written right now, ripe for usual suspects to hop on.

Alternative means

Mike 137

They probably mean to use Eventbrite, so the latter can abuse invitees' email addressess instead for electronic direct marketing (and profile them as well).

Lol

Aristotles slow and dimwitted horse

Stories like these always remind me of the one in El Reg from a number of years ago of the poor girl who accidentally replied to everyone in her office via an instant message as to how much she'd enjoyed giving one of her colleagues (in the same office) - a blowjob.

Re: Lol

Yet Another Anonymous coward

So that's why it's called BCC

Re: Blow by Blow Account

Anonymous Coward

Id forgotten this story - life sucks at times.

Re: Lol

JassMan

Reminds me of the time, a rather evangelical secretary kept sending everyone she had on her mailing list, stories about the good news of getting to know Jesus. One day she received a mail from GOD who reminded her that everyone was entitled to their own beliefs and suggested the office would be more productive if people only received work related mails on the office system. The shock of it all kept her off work for a week and a public reprimand (all be it with a followup private beer from the boss) of the spoofer so she could see the there were no gods involved the sending of emails.

Re: Lol

Yet Another Anonymous coward

>no gods involved the sending of emails.

Although sendmail config is believed to be the work of Cthullu

Re: Lol

Eclectic Man

What about the daemons?

They work really hard, you know.

Lessons will be learned!

alain williams

And then promptly forgotten.

Re: Lessons will be learned!

Doctor Syntax

And then promptly already forgotten.

We take our responsibility to safeguard personal data extremely seriously

sabroni

Yeah, I bet you do. I expect you have the full confidence of the Prime Minister too. That's another phrase that means precisely fuck all.

Re: We take our responsibility to safeguard personal data extremely seriously

Yet Another Anonymous coward

>That's another phrase that means precisely fuck all.

It means you're going to be fired within a week

Re: We take our responsibility to safeguard personal data extremely seriously

Eclectic Man

"It means you're going to be fired within a week"

Or that you have too much support in The Party to be got rid of just yet, or that the PM's waiting for an opportune moment to throw you under the bus to save him/her self. (See, e.g., Gavin Williamson, Chris Grayling etc.)

Style it out

wolfetone

"So thank you for all attending this conference, and I'm going to start by asking you a simple question - did you see how we sent your invitation email? Well that's rule number 1, don't do that"

Chris G

Considering the subject matter of the meeting, one wonders what the employment criteria are for applicants wanting to work at NHS Digital.

Recognising a lap top two out of three times?

I bet they think IT hygeine is dipping a pc into a bucket of Dettol.

Let's talk cyber

Warm Braw

Fatima's next job could be in Tesco's

(as she is currently being informed by HR)

Really, how?

chivo243

Shouldn't there be a limit on how many recipients can be added to the To: field? Better yet, if mass mailing is to be done, do it with a system that only allows the BCCs! Is this a thing? If not, and you develop it, remember you heard it here first!! I'll just have a few of these for compensation!

Pascal Monett

Yeah but the problem is always the same : as soon as you define rules to automate mailing, some idiot is going to feel that his case is special and he'll go out of his way to work around the rules and send it the way he wants.

You cannot automate against stupidity, stupidity will win every time. You need to educate stupidity.

With a cattle prod, if necessary.

Icon because integrated battery charge.

The last time I saw him he was walking down Lover's Lane holding his own hand.
-- Fred Allen