News: 1657870206

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Digital burglary at recruitment agency Morgan Hunt confirmed

(2022/07/15)


The bad news keeps on rolling for British recruitment agency Morgan Hunt amid confirmation it suffered a digital burglary, with intruders making off with the personal data for some of the freelancers on its books.

In a letter to contractors, Morgan Hunt – which provides personnel services to clients in the charity education, finance, government, housing and technology sectors – confirmed the break-in:

Morgan Hunt recently experienced a cyber security incident, in which one of our databases was impacted and an unauthorized third party gained access to our systems. Unfortunately, our investigations have shown that some of your personal data was contained on the accessed database and may have been copied.

The agency, which hires out interim, contract and temporary staff, wrote the letter the end of last month, according to one source. We have asked the company specifically when the leak happened.

In the message to contractors, it confirmed a third-party software developer was "improperly storing credentials to our database.

“We discovered that we were compromised by an unauthorized third party as a result of this, leading to some candidate data being accessed. We immediately took steps to address the issue, including working with external IT cyber-security experts to help investigate, manage and resolve the incident."

[1]

The info accessed on the database included contractors' names, contact details, identity documents, proof of address documents (including any bank or building society statement provided), National Insurance number, and date of birth.

[2]Funky Pigeon pauses all orders after 'security incident'

[3]Emma Sleep Company admits checkout cyber attack

[4]UK Ministry of Defence takes recruitment system offline, confirms data leak

[5]UK criminal defense lawyer hadn't patched when ransomware hit

Clients of Morgan Hunt's recruitment services [6]include United Colleges Group, YMCA, Dorset Council, Buckinghamshire Council and Tower Hamlet Homes.

As is typical in these types of circumstances, Morgan Hunt said that while there is "no evidence" to indicate its contractors will be impacted by the attack, caution is advised.

[7]

There is, it admitted, "a theoretical risk that in the wrong hands, some of the information could potentially be used to attempt to commit identity theft or fraud. While we believe this risk is low we recommend that you exercise increased vigilance in all matters relating to your personal details."

Morgan Hunt's last reported financial year, ended March 31, 2021, was a tough one commercially – as it was for many similar businesses during the pandemic. The company reported a 20.6 percent fall in turnover to £48.24 million ($57.1 million) but made an operating profit of £340,000 ($402,000) compared to an operating loss of £507,000 ($600,170) in the previous fiscal year. Reducing costs by laying off staff and office downsizing returned the profit-and-loss accounts to black ink.

[8]

Bad actors have used their nefarious skills in the recruitment sector on numerous occasions in the past year, including a digital break-in at [9]Optionis and [10]Giant Pay .

We have asked Morgan Hunt for additional comment. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YtE6v0FE5PJmvK4853S-qwAAABc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2022/04/19/funky_pigeon_security_incident/

[3] https://www.theregister.com/2022/04/04/emma_the_sleep_company_admits/

[4] https://www.theregister.com/2022/03/24/ministry_of_defence/

[5] https://www.theregister.com/2022/03/15/brit_solicitor_fined_for_failing/

[6] https://www.morganhunt.com/our-featured-employers

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YtE6v0FE5PJmvK4853S-qwAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YtE6v0FE5PJmvK4853S-qwAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2022/02/08/optionis_vice_society/

[10] https://www.theregister.com/2021/09/28/giantpay_confirms_cyberattack/

[11] https://whitepapers.theregister.com/



"In the wrong hands" they say

Dan 55

It will get into the wrong hands and identity fraud will be committed, that's how getting pwned works.

And from the quoted text it seems they couldn't even cough up for a year's worth of Experian fraud monitoring.

Third Party

Anonymous Coward

As a person that has been dropped from several contracts over the years in favour of dirt cheap overseas outsourcing, and then hired back when they fuck up, I'd be very curious to know where this "third party" dev is located.

UK Business Leaders...yes, local talent is significantly more expensive than overseas talent...but that doesn't make hiring local talent bad value for money...on the contrary. Value for money comes from what you get for the money, not how much money you can save by getting what you perceive to be the "same service".

"risk is low"

tiggity

I would have thought risk is quite high.

Data stolen included identity documents (so potentially scans of driving licence or passport), bank statements (acc no, sort code, account name, some transactions for those bank security questions you often get asked e.g. describe your regular direct debits), NI number.

All of those are very useful in identity fraud. Next level usefulness compared to just address etc.

Why not store some data offline?

H in The Hague

Quote from the article: "identity documents, proof of address documents (including any bank or building society statement provided)"

Why is that data even kept online? You would expect they only need that once, when they start working with somebody. Keeping it offline, possibly as hard copy in a filing cabinet would make it much easier to protect the data. Would cost a little more in storage and clerical expenses, but would make data protection compliance easier and cheaper, and would probably reduce ICO fines and legal hassle from folk whose PPI has been leaked.

Or does even thinking of that make me an old fossil?

I'd been wondering…

Anonymous Coward

> Bad actors have used their nefarious skills in the recruitment sector on numerous occasions in the past year, including a digital break-in at Optionis and Giant Pay.

…what Bruce Willis was getting up to these days.

Theoretical

Anonymous Coward

> There is, it admitted, "a theoretical risk that in the wrong hands, some of the information could potentially be used to attempt to commit identity theft or fraud.

What else are you going to steal the data for? As a hobby?

I remember Ulysses well... Left one day for the post office to mail a letter,
met a blonde named Circe on the streetcar, and didn't come back for 20 years.