Cumbrian cops accidentally publish all of its officers' details online
- Reference: 1692013123
- News link: https://www.theregister.co.uk/2023/08/14/cumbrian_police_accidentally_published_officer_details_online/
- Source link:
In this incident, the Cumbrian police admitted the names, salaries and allowances for all officers and staff were published to its website. It is understood to have occurred in the spring, and human error is being blamed for the unwitting disclosure.
In a statement, the force told The Register : "Cumbria Constabulary became aware of a data breach on Monday 6th March 2023 where information about the pay and allowances of every police officer and police staff roles as at 31st March 2022 was uploaded to the Constabulary's website, which was a human error."
[1]
The data also included names and positions of staff, but did not contain information about the locations where the posts were deployed or personal details such as address or date of birth, the statement said.
[2]
[3]
According to the force, the information was removed as soon as its inadvertent publication had been identified, but it did not say how long it had been online before the error was discovered.
Cumbria Constabulary said it immediately contacted all affected staff about the mistake, explained to them the impact of this disclosure was low and outlined the measures it had put in place to manage the leak and to prevent it happening again.
[4]
The incident was referred to the Information Commissioner's Office (ICO - the UK data regulator), the force told us. It claims the ICO determined that no further action was necessary, beyond giving some advice and recommendations. The ICO was satisfied with the actions the Constabulary had taken and the robust steps which were put in place to prevent any further data breaches.
The ICO confirmed this to us: "Cumbria Constabulary made us aware of an incident in March 2023. The information provided was carefully assessed and the organization provided details about the steps taken in response to the incident. We provided data protection advice and concluded that no further action was necessary. We assess reported incidents on a case-by-case basis and any action is based on the specific facts and circumstances."
The news follows [5]last week’s leak involving the Police Service of Northern Ireland (PSNI), where a spreadsheet containing details of serving police officers plus civilian staff members was mistakenly posted online.
[6]Electoral Commission had internet-facing server with unpatched vuln
[7]Northern Ireland police may have endangered its own officers by posting details online in error
[8]Criminal records office yanks web portal offline amid 'cyber security incident'
[9]UK police to spend tens of millions on legacy comms network kit
[10]UK government has 'no clear plan' for replacing ageing legacy IT estate, MPs report
That disclosure of information was potentially serious, as officers in Northern Ireland regularly face threats from extremists. While the police in Cumbria do not face the same kind of dangers, it is nonetheless worrying that two British forces should inadvertently publish information about their own officers within the space of a few months.
According to the [11]Financial Times , the PSNI is bracing itself for fines following the news of the incident.
[12]
Chief constable Simon Byrne was reported to have been given a “grilling” by the force's own oversight body, and said he was working on the assumption that it would be liable to penalties from the ICO or from officers bringing their own legal claims about the disclosure of their personal data. The ICO is currently investigating the incident. ®
Get our [13]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNpPrtPBNF@b4leqd6T@KgAAAYA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNpPrtPBNF@b4leqd6T@KgAAAYA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNpPrtPBNF@b4leqd6T@KgAAAYA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNpPrtPBNF@b4leqd6T@KgAAAYA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/08/09/psni_data_breach/
[6] https://www.theregister.com/2023/08/11/electoral_commission_vulnerability/
[7] https://www.theregister.com/2023/08/09/psni_data_breach/
[8] https://www.theregister.com/2023/04/06/acro_security_incident/
[9] https://www.theregister.com/2022/06/09/uk_police_legacy_airwave_bill/
[10] https://www.theregister.com/2021/12/13/uk_government_has_no_clear/
[11] https://www.ft.com/content/87b55444-1f9b-452d-b4e3-ee926dd4a607
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNpPrtPBNF@b4leqd6T@KgAAAYA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
How?
Having a set up where someone who has access to sensitve personal information also has unfettered access to publish to the website is asking for trouble.
Re: How?
It's not so much a question of access rights (I imagine it's a very small team), it's how on earth somebody had that document and actually thought "Yes, I'll upload this to the website", or mistakenly got the wrong document and then didn't think "I'll just go and check it's uploaded correctly" after publishing it.
Re: How?
Pretty much all the data held by a police force is potentially sensitive.
There really is no excuse for having a system in which it is even possible for data to be posted online without at least one other party actively reviewing the actual intended publication (and not a description, summary or original sources thereof). It's not an "accident", it's not "human error", it's a negligent failure of governance.
Re: How?
They could be in the same situation I found myself in once when having queried the wisdom of placing a document on the web site being told it wasn't my job to decide what got published. It was fun to see all the headless chickens running around half an hour or so later shouting take it down, take it down
For all the billions spent on giant...
Willy waving projects... Most IT systems on the planet seem to be run by someone in admin using an Excel spreadsheet saved to a shared drive (shared drive, intranet, internet, what's the difference?).
Re: For all the billions spent on giant...
I think that is most companies! Every company has a set of spreadsheets that are critical to ongoing operation where no-one can remember who created them, no-one knows how they actually work and no-one dares edit them!
Setting up some monster of a spreadsheet with lots of lookups and maths looks good to management but they end up out of date in a matter of weeks. We had an ordering form that was supposed to have all the project details and associated codes in a lookup. It was never maintained. The people filling it in didn't usually know the accounting codes as they were on a part of AX they had no permissions to. Accounts whinged and whined about badly filled in forms and when confronted about the fact that THEY allocated the codes and THEY had access to the relevant systems the response was 'not our job to update this form, it was written by xyz and they should update it'.
Another such ball-ache type document we used had a typo in a script. Whatever version of office we were using at the time didn't care. The next version threw an utter hissy fit and would take 5+ mins to open the docs. Productivity fell through the floor for a while :)
Re: For all the billions spent on giant...
Well there might be some people out there using Google Sheets, or Apple Numbers; but other than that everything ultimately runs on Excel. Including, I imagine, Google and Apple.
No reason to worry
As they'll tell you themselves, "if you have nothing to hide you have nothing to fear", isn't it...
Re: No reason to worry
Or... nothing to hide - then they'll fit you up with something.
This data SHOULD all be public. These are government employees, employees of the public. The public should have a right to know their names and how much they're being paid.
Give whoever put this online a medal.
To make this data access a little safer then we need to upgrade 2FA to 20FA to try and prevent this sort of event from happening so often ... hacking is not easy but it's not impossible is it?
El Reg, I will please ask for a new icon update again ... a pair of wire cutters to refer to the guarantee of data safety.
Dear AC, please read the Data Protection Act 2018. It’s not a particularly long read, but it is the law. You want your next door neighbour to have access to your personal sensitive information? Tax records? Medical records? Didn’t think so.
Please tell me you aren't really that stupid?
No one needs to know the names and locations of Police Officers. You do know what would happen to officers and their families if every crook and terrorist had access to that information?
I'm pretty sure info about how much we pay people in the public sector IS available, just anonymised.
Long ago someone managed to get hold of a document with the salaries of EVEYONE at the company. I believe it was in a ring binder just sat on a shelf in the admin area of the office.
Oh my that kicked up a heck of a fuss as it revealed disparities between teams and that they had ramped graduate salaries above the level of pay that people who'd been there 1-2 years were on. Not sure anyone got an arse kicking for that.
employees of the public. The public should have a right to know their names and how much they're being paid.
Under transitive closure everybody with a job is an employee of the public(*).
(*) Unless you're only selling to the aliens that the US Congress was so interested in.
Rejoyce!
The £25m NHS data transfer deal to Palantir and recent leaks from the Electoral Commission, PSNI, this, and others means essential UK population data won't be lost. Putting data out to tender on the internet so organisations can make copies represents best value for money for the British taxpayer.
Re: Rejoyce!
Well, backup is vital, and multiple copies is good.
The infernal spreadsheet
The creators of Excel and predecessor apps must be spitting feathers to know how misused their baby has become. Hmm let’s just lob this spreadsheet online, never mind what else it might contain. Releasing anything like this to a website should go through proper scrutiny and should be the exception rather than the rule. Review it like you personally will end up in court, and you won’t go far wrong.
Quote: the PSNI is bracing itself for fines...
Which will be paid by the taxpayer. Whenever a public body is fined, the fines are ultimately paid by the taxpayer. Whenever a private company is fined such as a water or energy utility, the fines are ultimately paid by their customers. Regulators and the courts exist to give the impression of justice being done. We are being conned and we are paying for the privilege.
Re: Quote: the PSNI is bracing itself for fines...
The fines don't need to be huge, they just need to be personally targeted at the people responsible for either breaching their responsibilities, or implementing such weak governance that allowed it to happen.
I'm sure that the equivalent of 6 months salary would be a suitable fine to make people more careful.
I remember when I was working at a UK Bank, it was drummed into us that regulatory fines for not following money laundering protocols were levied directly against the people not following procedure (and I was not even in a position where I could affect any money flow!)
If this can be right for bank cashiers, then surely it could be done for other entities, especially public ones.
Good job
EXCELlent work everyone.