Royal Mail customer data leak shutters online Click and Drop
- Reference: 1667464153
- News link: https://www.theregister.co.uk/2022/11/03/royal_mail_customer_data_leak/
- Source link:
The data leak started around 13:00 GMT, and according to an [1]alert posted on Click and Drop's status page, Royal Mail shut down the website about an hour later.
In an update posted shortly before 14:00 GMT, the postal service noted:
We have been made aware there was an issue affecting Click & Drop that meant some customers could see other customers' orders. As a protective measure, we have stopped access to Click & Drop temporarily. We fully understand and apologise for the inconvenience caused by this. Our engineers are working as hard as possible to get the site back up and running as expected. Further updates will be posted here as soon as we have more information.
In subsequent alerts, Royal Mail assured customers that its engineers continued to work on a fix, and hoped to have the site back online "as soon as possible." The service, which allows customers to print labels and pay for postage online, and then track packages until they reach their destination, vowed that it was "treating this as the highest priority."
Later, Royal Mail suggested users resort to actual paper "emergency" order forms instead of the online versions. Who even owns a printer these days? Emergency, indeed.
[2]
About four hours later, at 18:01 GMT, the postal service marked the issue as "resolved," and the website was up and running. "We apologise for any inconvenience this has caused our customers," Royal Mail said. "The root cause is now under investigation."
[3]
[4]
On Wednesday, the online service noted "no incidents reported today." However, some customers took to Twitter to say the site [5]still wasn't working , and they had been [6]charged twice but not received any postage label.
[7]Education tech giant gets an F for security after sensitive info on 40 million users stolen
[8]Health insurer Medibank's data breach diagnosis keeps getting worse
[9]TikTok faces $29m fine for 'failing to protect UK kids' privacy'
[10]Gone phishing: UK data watchdog fines construction biz £4.4m for poor infosec hygiene
Royal Mail did not immediately respond to The Register 's questions about how many customers' data was exposed, or whether the incident was due to a mistake or something more malicious.
As of Tuesday, Royal Mail had not notified the UK's Information Commissioner's Office (ICO), according to Sky News. The postal service has 72 hours after becoming aware of a data breach to notify the consumer privacy watchdog agency, unless the leak doesn't "pose a risk to people's rights and freedoms" an ICO spokesperson [11]told the media outlet.
The ICO didn't immediately respond to The Register 's inquiry. ®
Get our [12]Tech Resources
[1] https://clickanddrop.statuspage.io/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y2OfUWJi6Ezfa0jeq9kcDQAAAFA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2OfUWJi6Ezfa0jeq9kcDQAAAFA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2OfUWJi6Ezfa0jeq9kcDQAAAFA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://twitter.com/djdbm/status/1587799287823491072
[6] https://twitter.com/littleshopofpo1/status/1587794343796117504
[7] https://www.theregister.com/2022/10/31/chegg_ftc_order/
[8] https://www.theregister.com/2022/10/26/medibank_breach_update/
[9] https://www.theregister.com/2022/09/26/tiktok_uk_ico_privacy/
[10] https://www.theregister.com/2022/10/25/gone_phishing_uk_data_watchdog/
[11] https://news.sky.com/story/royal-mail-data-breach-as-customers-information-leaked-to-other-users
[12] https://whitepapers.theregister.com/
Re: "charged twice but not received any postage label"
Royal Mail and the Post Office separated in 2011.
Facts?
" The service, which allows customers to print labels...." Followed by the comment "Who even owns a printer these days?" I think if you read your own article you have to own a printer to use the service.
Allowing interns to copy and paste again El Reg?
Re: Facts?
Maybe they have used Royal Mails collection by your postie option, there is an option for them to bring a label.
Re: Facts?
You don't need a printer to use the service. There's the option to have Royal Mail print the labels for you upon collection or drop-off.
Re: Facts?
Correct. Our labels get squired out to a Zebra dedicated printer onto stickers provided by the Royal Mail.
ICO Notification is in the post
Post office has naturally posted their ICO notification and awaiting for their world class delivery team to deliver.
It’ll probable be returned to sender for lack of adequate postage or they can’t find the ICO.
Re: Regional data centres
More likely "We attempted delivery but nobody was in, so we've delivered it to a random neighbour" (not telling you which one!).
When I worked for the Post Office
Anything after 12 noon was left to tomorrow.
We were very serious drinkers back then.
I wonder what the excuse is these days.
nationalise Royal Mail
Or better yet, go back in time and not take it private.
"charged twice but not received any postage label"
Sounds like Fujitsu got the contract again and they are still seemingly unaware of how transactions are supposed to work.
Can we look also look forward to the Royal Mail taking innocent customers to court?