Digital burglary at recruitment agency Morgan Hunt confirmed
- Reference: 1657870206
- News link: https://www.theregister.co.uk/2022/07/15/digital_burglary_at_recruitment_agency/
- Source link:
In a letter to contractors, Morgan Hunt – which provides personnel services to clients in the charity education, finance, government, housing and technology sectors – confirmed the break-in:
Morgan Hunt recently experienced a cyber security incident, in which one of our databases was impacted and an unauthorized third party gained access to our systems. Unfortunately, our investigations have shown that some of your personal data was contained on the accessed database and may have been copied.
The agency, which hires out interim, contract and temporary staff, wrote the letter the end of last month, according to one source. We have asked the company specifically when the leak happened.
In the message to contractors, it confirmed a third-party software developer was "improperly storing credentials to our database.
“We discovered that we were compromised by an unauthorized third party as a result of this, leading to some candidate data being accessed. We immediately took steps to address the issue, including working with external IT cyber-security experts to help investigate, manage and resolve the incident."
[1]
The info accessed on the database included contractors' names, contact details, identity documents, proof of address documents (including any bank or building society statement provided), National Insurance number, and date of birth.
[2]Funky Pigeon pauses all orders after 'security incident'
[3]Emma Sleep Company admits checkout cyber attack
[4]UK Ministry of Defence takes recruitment system offline, confirms data leak
[5]UK criminal defense lawyer hadn't patched when ransomware hit
Clients of Morgan Hunt's recruitment services [6]include United Colleges Group, YMCA, Dorset Council, Buckinghamshire Council and Tower Hamlet Homes.
As is typical in these types of circumstances, Morgan Hunt said that while there is "no evidence" to indicate its contractors will be impacted by the attack, caution is advised.
[7]
There is, it admitted, "a theoretical risk that in the wrong hands, some of the information could potentially be used to attempt to commit identity theft or fraud. While we believe this risk is low we recommend that you exercise increased vigilance in all matters relating to your personal details."
Morgan Hunt's last reported financial year, ended March 31, 2021, was a tough one commercially – as it was for many similar businesses during the pandemic. The company reported a 20.6 percent fall in turnover to £48.24 million ($57.1 million) but made an operating profit of £340,000 ($402,000) compared to an operating loss of £507,000 ($600,170) in the previous fiscal year. Reducing costs by laying off staff and office downsizing returned the profit-and-loss accounts to black ink.
[8]
Bad actors have used their nefarious skills in the recruitment sector on numerous occasions in the past year, including a digital break-in at [9]Optionis and [10]Giant Pay .
We have asked Morgan Hunt for additional comment. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YtE6v0FE5PJmvK4853S-qwAAABc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2022/04/19/funky_pigeon_security_incident/
[3] https://www.theregister.com/2022/04/04/emma_the_sleep_company_admits/
[4] https://www.theregister.com/2022/03/24/ministry_of_defence/
[5] https://www.theregister.com/2022/03/15/brit_solicitor_fined_for_failing/
[6] https://www.morganhunt.com/our-featured-employers
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YtE6v0FE5PJmvK4853S-qwAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YtE6v0FE5PJmvK4853S-qwAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2022/02/08/optionis_vice_society/
[10] https://www.theregister.com/2021/09/28/giantpay_confirms_cyberattack/
[11] https://whitepapers.theregister.com/
Third Party
As a person that has been dropped from several contracts over the years in favour of dirt cheap overseas outsourcing, and then hired back when they fuck up, I'd be very curious to know where this "third party" dev is located.
UK Business Leaders...yes, local talent is significantly more expensive than overseas talent...but that doesn't make hiring local talent bad value for money...on the contrary. Value for money comes from what you get for the money, not how much money you can save by getting what you perceive to be the "same service".
"risk is low"
I would have thought risk is quite high.
Data stolen included identity documents (so potentially scans of driving licence or passport), bank statements (acc no, sort code, account name, some transactions for those bank security questions you often get asked e.g. describe your regular direct debits), NI number.
All of those are very useful in identity fraud. Next level usefulness compared to just address etc.
Why not store some data offline?
Quote from the article: "identity documents, proof of address documents (including any bank or building society statement provided)"
Why is that data even kept online? You would expect they only need that once, when they start working with somebody. Keeping it offline, possibly as hard copy in a filing cabinet would make it much easier to protect the data. Would cost a little more in storage and clerical expenses, but would make data protection compliance easier and cheaper, and would probably reduce ICO fines and legal hassle from folk whose PPI has been leaked.
Or does even thinking of that make me an old fossil?
I'd been wondering…
> Bad actors have used their nefarious skills in the recruitment sector on numerous occasions in the past year, including a digital break-in at Optionis and Giant Pay.
…what Bruce Willis was getting up to these days.
Theoretical
> There is, it admitted, "a theoretical risk that in the wrong hands, some of the information could potentially be used to attempt to commit identity theft or fraud.
What else are you going to steal the data for? As a hobby?
"In the wrong hands" they say
It will get into the wrong hands and identity fraud will be committed, that's how getting pwned works.
And from the quoted text it seems they couldn't even cough up for a year's worth of Experian fraud monitoring.