Another security calamity for Capita: An unsecured AWS bucket
- Reference: 1684327701
- News link: https://www.theregister.co.uk/2023/05/17/another_security_calamity_for_capita/
- Source link:
Colchester City Council [1]said on Monday it had launched a probe following the discovery of the open bucket, and was working with Capita to fully understand the “extent of the data spill and take all necessary steps to minimize any impact on residents.”
In the latest update, the [2]council said today that Capita had been “entrusted with the crucial task” of running the end-of-year auditing services for the council tax and benefits. This, it added, included extracting data from the council’s own systems.
[3]
The information exposed detailed the benefits local resident received in fiscal years 2019/20 and 2020/21. The council said in a statement:
[4]
[5]
“The data, along with similar information from other local authorities, was found on an unsecured Amazon Data Bucket controlled by Capita. Capita has confirmed that it has since been made secure and we can confirm that the data does not include any bank details.”
It is unacceptable that Capita has failed to meet these required standards
Colchester city council has asked for more information from Capita to confirm the “extent of the breach as quickly as possible,” and says it was told there is no evidence, as yet, of any malicious use of the data.
Richard Block, Colchester City Council’s chief operating officer, said in a statement he was “extremely disappointed that such a serious data breach by one of our contractors has occurred.”
“We require all parties involved in the handling of sensitive information to adhere to the highest standards of data protection and it is unacceptable that Capita has failed to meet these required standards. As a result, we are considering what further action may be appropriate regarding Capita.
[6]
“Upon becoming aware of this incident, the records in question were immediately secured, and we continue to investigate the incident to ensure that all necessary measures are, and remain, in place. We have reported the incident to the appropriate regulatory authorities and will cooperate fully with any investigation or any further actions required."
He said Capita had provided assurances that no personal bank details of the citizens whose data was exposed have been compromised. “We expect a full explanation and remedy from the company and for them to apologize directly to those affected.”
Capita is the largest British business process outsourcing and professional services company, it has some £6.5 billion ($8.1 billion) of contracts under its belt, including with many of Britain’s central government departments.
[7]
A spokesperson at Capita said in a statement: “We are working with our third-party technical advisors to investigate this issue. The data is secure and no longer accessible. Our investigations into the matter are ongoing. The privacy and security of our client information is of the utmost importance to us.”
[8]Capita looking at a bill of £20M over breach clean-up costs
[9]Leaky AWS S3 buckets are so common, they're being found by the thousands now – with lots of buried secrets
[10]Twilio: Someone waltzed into our unsecured AWS S3 silo, added dodgy code to our JavaScript SDK for customers
[11]McGraw Hill's S3 buckets exposed 100,000 students' grades and personal info
[12]Security company finds unsecured bucket of US military images on AWS
This latest development comes on the heels of Capita shutting down its part of its internal systems in [13]late March after detecting a digital break-in of its infrastructure, which the outsourcing giant admitted to in [14]early April . Russian ransomware crew [15]Black Basta has claimed responsibility .
Capita subsequently said [16]4 percent of its server estate had been accessed and it had some evidence of data exfiltration. It later updated investors to say around [17]0.1 percent of its servers has been accessed .
Last week, the UK’s largest private pension scheme said Capita had written to it to warn that details of [18]470,000 active, deferred and retired members was held on the servers that were accessed by the intruder or intruders. This includes names, date of birth and National Insurance numbers. The data, the Universities Superannuation Scheme added, might not have been stolen but it was laboring on the assumption that “it was.” ®
Get our [19]Tech Resources
[1] https://www.colchester.gov.uk/info/cbc-article/?id=KA-04376
[2] https://www.colchester.gov.uk/info/cbc-article/?catid=latest-news&id=KA-04379
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZGT6J1bCESe4tVt0v7nfEwAAAMY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGT6J1bCESe4tVt0v7nfEwAAAMY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGT6J1bCESe4tVt0v7nfEwAAAMY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGT6J1bCESe4tVt0v7nfEwAAAMY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGT6J1bCESe4tVt0v7nfEwAAAMY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2023/05/10/capita_breach_costs/
[9] https://www.theregister.com/2020/08/03/leaky_s3_buckets/
[10] https://www.theregister.com/2020/07/21/twilio_javascript_sdk_code_injection/
[11] https://www.theregister.com/2022/12/20/mcgraw_hills_s3_buckets_exposed/
[12] https://www.theregister.com/2017/06/01/us_national_geospatial_intelligence_agency_leak/
[13] https://www.theregister.com/2023/03/31/capita_confirms_it_outage/
[14] https://www.theregister.com/2023/04/03/capita_confirms_security_attack_as/
[15] https://www.theregister.com/2023/04/18/capita_breach_gets_worse/
[16] https://www.theregister.com/2023/04/20/capita_admits_to_evidence_that/
[17] https://www.theregister.com/2023/05/10/capita_breach_costs/
[18] https://www.theregister.com/2023/05/12/uks_largest_private_pension_scheme/
[19] https://whitepapers.theregister.com/
Re: Blah blah blah
Weirdly their incompetence also demonstrates why they are necessary.
So when something like this does go down, the council can offload all the blame on someone else and not have to worry about the aftermath.
Muppets - no open buckets are cloud 101.
Is Crapita not using even a simple 'how to' script to set up new ones as crapita access only - start secure.
Re: Muppets - no open buckets are cloud 101.
> Is Crapita not using even a simple 'how to' script to set up new ones as crapita access only - start secure.
This is what happens when you get an unpaid intern to do your fintech /s
What's not said is who discovered this. Are Capita, prompted by pension scheme breach, doing an audit and discovered it themselves? Did one of their customers decide to run a check? Or was it some 3rd party of whatever colour hat?
"No bank details" - Whoopee fucking do
There will still be more than enough for motivated scamsters to target individuals and begin stealing their identities to get these bank details.
Blah blah blah
-> Capita is facing criticism
But NO action. The contracts with Capita will continue until all information is leaked. Then the leaking of information will be termed uninmportant.