More UK councils caught by Capita's open AWS bucket blunder
- Reference: 1684757581
- News link: https://www.theregister.co.uk/2023/05/22/capita_security_pensions_aws_bucket_city_councils/
- Source link:
Colchester City Council was the [1]first to step forward last week to claim that tech provider Capita had messed up in its auditing services contract for multiple authorities. Capita, it said, had left local residents' benefits data exposed to the public internet and said the council was trying to detect the "extent of the data spill."
The data for Colchester pertained to financial years 2019/20 and 2020/221, and the city council said it was "considering what further action may be appropriate regarding Capita."
[2]
Others have [3]subsequently confirmed their data was left out in the open, including Coventry City Council, Adur and Worthing, Rochford District Council, Derby City Council, and South Staffordshire.
[4]
[5]
Alison Parkin, director of financial services at Derby CC, said Capita supported its council tax and benefits service, and data left exposed was collected in early 2021. "We're very disappointed to hear about the incident," she said.
"We know this incident will cause concern, and we would like to apologize to our customers, We will be contacting affected customers individually," Parkin continued, adding: "As part of our investigation, we will also be taking the opportunity to review the arrangements with Capita."
[6]
A spokesperson for Coventry CC told us it had been "belatedly informed that there has been a potential historic data breach by our financial services contractor Capita.
"We are extremely concerned and disappointed by this news, not just because we take such matters very seriously, but also the length of time it took talent us," the statement added.
"The council is committed to ensuring Capita works with us to fully understand if there has been any data breach and to implement measures to prevent a similar incident from occurring in the future. We are waiting for further clarification from Capita."
[7]
Rochford District is also trying to determine how the information was left unsecured online. Tim Willis, interim director of resources, said in a statement:
"We take very seriously our commitment to safeguarding the privacy and security of our residents' personal information. We know this will cause concern to residents and we want to apologize to those affected on behalf of Capita. We will be working with Capita to review the company's processes and ensure the avoidance of any further breaches."
South Staffordshire told us it was awaev of a "potential issue" with a third party supplier connected to data storage, and has informed the Information Commissioner's Office.
"The full extent of the issue is not yet fully known, however we have been assured that a full investigation is underway – the outcome of which will determine our next steps."
We asked Adur and Worthing to comment.
A spokesperson at Capita said: "We are working with our third-party technical advisors to investigate this issue. The data is secure and no longer accessible. Our investigations into the matter are ongoing. The privacy and security of our client information is of the utmost importance to us."
Capita is also dealing with a security incident from March, one in which its systems were broken into by criminals that stole data that Capita previously said was contained to a 0.1 percent of its server estate. Included in the servers accessed was pension data, and Capita has since written to clients warning that is a chance their data was exfiltrated.
The UK's largest private pension fund, USS, has already [8]warned members of the potential risks , and now retailer M&S has [9]written to clients , saying its scheme was "one of many Capita clients impacted" by the [10]March break-in .
"Following a detailed investigation, Capita has also confirmed that unfortunately the incident may have affected the security of personal data for a large proportion of our Scheme's members. This includes the majority of the Scheme's pensioner members and a very small group of deferred members.
"Capita cannot be certain that this data has been accessed, but we believe it's appropriate to act as if this is the case and warn affected members about the potential risks. There is the possibility that if personal data is accessed it could be used for fraud, identity theft or to send malicious emails."
[11]Capita: Cyber-attack broke some of our IT systems
[12]Capita IT breach gets worse as Black Basta claims it's now selling off stolen data
[13]Capita has 'evidence' customer data was stolen in digital burglary
[14]Capita admits some pension data 'likely' to have been accessed in March breach
[15]Capita looking at a bill of £20M over breach clean-up costs
[16]Britain's largest private pension scheme reveals scale of Capita break-in
[17]Another security calamity for Capita: An unsecured AWS bucket
British alcoholic beverage maker [18]Diageo – which wons the brands Guinness, Gordon's Gin and Johnnie Walker, among others – confirmed to the FT that some of its 32,000 pension members were impacted by the breach and it was still trying to determine the extent. It added that members' benefits were safe.
On the pensions' issue, Capita told us:
"Capita continues to work closely with specialist advisers and forensic experts to investigate the incident and we have taken extensive steps to recover and secure the data. In line with our previous announcement, we are now informing those we have identified to be affected. We have worked quickly to provide our clients with information, reassurance and support, while delivering for them as a business. In instances where we need to provide further support to those affected, we will do so." ®
Get our [19]Tech Resources
[1] https://www.theregister.com/2023/05/17/another_security_calamity_for_capita/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZGuRpq2n6dwcThJs7@RcbQAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.ft.com/content/ff150b65-8dc6-48c8-b2e4-6b8fbee4ea03
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGuRpq2n6dwcThJs7@RcbQAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGuRpq2n6dwcThJs7@RcbQAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGuRpq2n6dwcThJs7@RcbQAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGuRpq2n6dwcThJs7@RcbQAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2023/05/12/uks_largest_private_pension_scheme/
[9] https://www.mandspensionscheme.com/news/news/2023/05/message-from-the-trustee-important-update-on-capita-cyber-incident
[10] https://www.theregister.com/2023/05/05/capita_pension_data_breach/
[11] https://www.theregister.com/2023/04/03/capita_confirms_security_attack_as/
[12] https://www.theregister.com/2023/04/18/capita_breach_gets_worse/
[13] https://www.theregister.com/2023/04/20/capita_admits_to_evidence_that/
[14] https://www.theregister.com/2023/05/05/capita_pension_data_breach/
[15] https://www.theregister.com/2023/05/10/capita_breach_costs/
[16] https://www.theregister.com/2023/05/12/uks_largest_private_pension_scheme/
[17] https://www.theregister.com/2023/05/17/another_security_calamity_for_capita/
[18] https://www.ft.com/content/ff150b65-8dc6-48c8-b2e4-6b8fbee4ea03
[19] https://whitepapers.theregister.com/
Re: Reg - please check the speeling in this raticle
"the length of time it took talent us" and "which wons the brands Guinness" jumped off the page and slapped me in the face! :(
Re: Reg - please check the speeling in this raticle
It's world Grauniad day... celebrating journos of the past.
Re: Reg - please check the speeling in this raticle
"it was awaev of a "potential issue""
From mistakes in other articles, it is starting to look intentional.
"we take very seriously..."
which is why they 1. outsourced to 2. the lowest bidder.
Another untruism
"The privacy and security of our client information is of the utmost importance to us." ... Which is why the second party outsourced *again*, to a third party. They should check the definition of utmost, it's not the same as passing the buck. "We do only what is spelt out in the contract, to the minimum standard allowed by our lack of talent." FTFY
Well, they (the councils) are expected to deliver value for money by their constituents, so any penny counts (especially if it comes to keeping their pension management costs down). But this breach widening and catching more and more organisations out means that Capita cannot be trusted and should a) lose all the contracts, and b) be fined to yazoo (without being able to recover the costs from the councils through charges). Oh, and paying for fraud monitoring for *every* member of the public impacted, that would be nice too.
It's time that organisations like Capita learn that you. do. not. fuck. with. personal. data. without. consequences!!
And the contracts
kept rolling in. And the Capita shareholders laughed like they were on a mixture of funny pills and laughing gas all the way to their offshore banks.
They know how to
Crap-IT-All with your data.
"We are working with our third-party technical advisors to investigate this issue"
Is that the new name for sitting in a conference room, holding your head in your hands, repeating "f**k, f**k, f**k"? Because there is little else to do.
The bad news train keeps rolling for Capita
Not really. Bad news for the poor ordinary folks who will now have to watch their finances for pretty well "for ever' (I bet the data thieves know to wait until the free enhanced monitoring expires), but basically no effect on lucrative future contracts.
Points of order
"We have taken extensive steps to recover and secure the data."
How? Secure, maybe, but you can't recover it once it's out in the wild.
"We have worked quickly to provide our clients with information"
Not according to the impacted customers in the very statements your spokesface was countering.
Until line managers are fined/jailed for such IT mismanagement, this will keep happening - this isn't a sophisticated cyber hack which would offer a fig leaf of defence: This is an unsecured AWS bucket, the type of misconfiguration we've been warning about for over a decade.
Reg - please check the speeling in this raticle
see titel