Northern Ireland police may have endangered its own officers by posting details online in error
- Reference: 1691586015
- News link: https://www.theregister.co.uk/2023/08/09/psni_data_breach/
- Source link:
The data leak involved a spreadsheet detailing the surnames and initials of all serving officers in the Police Service of Northern Ireland (PSNI), plus civilian staff members. It listed their rank or grade, plus location and department in which they work, but no other personal information such as private addresses is said to have been included.
In an [1]official statement , the PSNI said the breach resulted from information included in error in response to a Freedom of Information (FoI) request, and was taken down quickly, but the service does not appear to know whether the information in the spreadsheet was accessed while it was online.
[2]
According to The Times newspaper, the FoI request had sought a breakdown of PSNI officers and staff by rank and grade, but a full spreadsheet was included by mistake.
[3]
[4]
"Although it was made available as a result of our own error, anyone who did access the information before it was taken down is responsible for what they do with it next. It is important that data anyone has accessed is deleted immediately," said Assistant Chief Constable Chris Todd, the PSNI's Senior Information Risk Owner.
The PSNI said that an initial notification has been made to the Information Commissioner's Office (ICO) regarding the data leak, and that officers are investigating the circumstances surrounding the release of the data.
[5]
"The matter is being fully investigated and a Gold structure is in place to oversee the investigation and consequences. It is actively being reviewed to identify any security issues," Todd said.
According to The Guardian newspaper, the data was uploaded around 2:30pm and was visible to the public for two and a half to three hours. Some news reports claim that some of the details have already been shared on social media messaging groups.
We asked the PSNI if there was any indication that the spreadsheet was accessed during the time it was online, but a spokesperson told us that there was nothing further to add beyond the information available in the official statement.
[6]
This is the second significant data incident involving a notable public body in the UK this week, following the [7]attack on the Electoral Commission disclosed yesterday, raising questions about how seriously data security is being taken by such organizations in the country.
There are differences in the two incidents, of course, as the Electoral Commission's infrastructure was infiltrated by an unknown attacker, likely a hostile state, while the PSNI data breach was due to the unintentional disclosure of sensitive information by the organization itself.
[8]UK voter data within reach of miscreants who hacked Electoral Commission
[9]Brit healthcare body rapped for WhatsApp chat sharing patient data
[10]Millions of people's data stolen because web devs forget to check access perms
[11]Medical files of 8M-plus people fall into hands of Clop via MOVEit mega-bug
However, the PSNI's mistake could have serious consequences, as the police in Northern Ireland still face threats from extremists on both sides of the region's sectarian divide, despite the signing of the Good Friday Agreement 25 years ago.
In a statement, the Chair of the Police Federation for Northern Ireland, Liam Kelly, called the incident "a breach of monumental proportions" and said an urgent inquiry is now required.
"We're fortunate that the PSNI spreadsheet didn't contain officer and staff home addresses, otherwise we would be facing a potentially calamitous situation," Kelly said.
"Inadequate or poor oversight of FoI procedures must be addressed and addressed urgently. New safeguards are obviously required to prevent this from ever happening again."
Richard Forrest, Legal Director at UK law outfit Hayes Connor, said it was concerning how a data breach of this magnitude could happen within the justice sector. "The majority of data breach cases we see are down to human error. This case is no different, highlighting the crucial need for better staff training on how to handle personal data to prevent such risks to employees," he said.
Official threat level: Severe
The official threat level from Northern Ireland-related terrorism currently stands at severe, which means an attack is considered highly likely, and is just one step down from the maximum threat level.
"This is an issue we take extremely seriously and as our investigation continues we will keep the Northern Ireland Policing Board and the Information Commissioner's Office updated," Todd said.
In a [12]posting on Twitter*, Secretary of State for Northern Ireland Chris Heaton-Harris said: "I'm deeply concerned by the data breach involving the PSNI. My officials are in close contact with senior officers and are keeping me updated." ®
*Yes, we're still calling it Twitter.
Get our [13]Tech Resources
[1] https://www.psni.police.uk/latest-news/police-service-northern-ireland-statement-data-breach
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNO4I9XOQsGAXAW7ZGX@lQAAARI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNO4I9XOQsGAXAW7ZGX@lQAAARI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNO4I9XOQsGAXAW7ZGX@lQAAARI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNO4I9XOQsGAXAW7ZGX@lQAAARI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNO4I9XOQsGAXAW7ZGX@lQAAARI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2023/08/08/uk_electoral_commission_hacked_voter/?td=rt-3a
[8] https://www.theregister.com/2023/08/08/uk_electoral_commission_hacked_voter/
[9] https://www.theregister.com/2023/08/03/nhs_ico_warning/
[10] https://www.theregister.com/2023/07/29/cisa_nsa_idor_australia/
[11] https://www.theregister.com/2023/07/27/maximus_deloitte_moveit_hack/
[12] https://twitter.com/chhcalling/status/1689008361076035585
[13] https://whitepapers.theregister.com/
this is what i was thinking, surely the police if anyone should know what "Chain of custody" means.
Before handing off or accepting anything, review it carefully. Before sending it out have a second person sign off on it. Especially when it's the PSNI of all places!
Chain of custody applies to potential court exhibits. This is likely to be clerical staff at Castlereagh or wherever HQ is these days. They may nothing about chain of custody but releasing information without sign-off seems incomprehensible. A sign-off of this is even less comprehensible. Someone might be in line for a posting to Rockall.
while the PSNI data breach was due to the unintentional disclosure
No, no... In this day and age you'll want to spin that as "an intentional leak by a foreign threat actor embedded within the country's security services".
Well, it sounds more credible than "the guy in charge [ couldn't be arsed | was too busy | is too important for this trivial crap ] (delete as applicable). so he told the secretary to post a bunch of things - and she did exactly as was asked of her" which is perhaps closer to reality but much less exciting.
Re: while the PSNI data breach was due to the unintentional disclosure
Something similar but less harmful to real people happened at a company I worked for years ago.
A secretary was asked to print and fax a relatively long document to a prospective customer.
As a side note this place was pretty backwards as some of the senior management had their secretaries print out emails that had been sent to them.
Anyway, secretary goes to the printer, picks up wodge of paper from the output tray and feeds it to the fax machine. Not long after the sales person gets a rather irate call from the prospective customer as it turns out the wodge of paper had included someone elses printout as well and this was an internal sales doc detailing pricing, discounts etc. The prospective customer discovered they were being taken for a bit of a ride!
Same company, someone external was sent a word doc with all the change tracking info still intact. Oops! Suddenly everyone got a PDF writer installed and a very strict 'NO word docs via external email EVER!' memo came around.
Ulster Says No
To processes that prevent the details of their police force from being published to the public.
Virtually every one of Brendan Behan's original comments still applies 100% these days and they all keep me laughing, for example ...
"I have never seen a situation so dismal that a policeman couldn't make it worse."
Unintentional?
This is way beyond FUBAR
Re: Unintentional?
Not sure why the surprise... that's the "SN" in SNAFU
Re: Unintentional?
The incompetent lead the incompetent to incompetent incompetence.
And yet, one still wonders why nobody gets sacked for gross incompetence.
Re: Unintentional?
one still wonders why nobody gets sacked for gross incompetence
Sacking for incompetence is a tricky one, as technically the employee is not at fault. Incompetence means that the employee is not skilled enough to do their job (as opposed to negligence, where they should be able to do theitr job, but failed to do so).
Recruitment of someone who is capable of doing the job, i.e. is competent, is the responsibility of the employer.
That means that dismissal for incompetence carries the implication that the employer is the villain of the piece (for making an incorrect hiring decision) rather than the employee being at fault.
A modest proposal
Let's declare using Excel as a pseudo database to be possessing material that could be of use to terrorists and jail anybody who does it for a long time.
Human error, poor policy or slack management?
According to the [1]Irish Times , PSNI assistant chief constable Chris Todd stated “ There are steps and measures that we take to sign off releases through Freedom of Information requests [..] They differ in different circumstances. [...] Because the data shouldn’t have been sensitive, it should have just been numbers of officers and staff at every rank and grade, it only required a certain level of sign-off. [...] Regrettably, those measures were not sufficient for all the people in the chain to identify that embedded in what seemed like a very innocent and sensible release was further source data. "
This suggests that the basis for the confidentiality decision was solely the nature of the request. It should have primarily been the classification of the source, and only secondarily the nature of the request, i.e. documents at or above a specific classification should never be shared with 3rd parties. To fulfil an FoI request where a document at such a classification is involved, the relevant data alone should always be abstracted, and the result verified to be safely releasable. It appears in this case (as in the now infamous HMRC case) that the entire spreadsheet was simply published without consideration of its sensitivity, and clearly there were no adequate checks, including any adequately obvious document classification level..
Effective policy should preclude errors of this kind, but I have to admit that in two decades of consulting I've seldom if ever encountered a really effective policy, if for no other reason that in general policies simply don't get followed in practice. Even where they are adequate in principle, they generally get signed off against and forgotten and then everyone just wings it, or at best they start out being followed but familiarity breeds complaisance so normalised deviance sets in to the eventual point that the policy ceases to operate without anyone noticing.
Like everything else in the infosec arena, if it's going to actually work policy compliance must be continuously monitored against robust clearly defined standards and any deviance corrected.
[1] https://www.irishtimes.com/ireland/2023/08/08/psni-staff-and-civilians-affected-in-major-data-breach/
It seems incredible that there should be no process for responding to FoI requests that doesn't involve a review of the material released sufficiently careful to trap this.
Also the site which published it should also have known better giving that is personal data. In the circumstances I'd expect that at least there would be a DPA offence in there if not criminal charges given the data subjects.