You're not seeing double – yet another UK copshop is confessing to a data leak
- Reference: 1692098905
- News link: https://www.theregister.co.uk/2023/08/15/norfolk_and_suffolk_police_data_breach/
- Source link:
The latest blunder follows a litany of recent errors elsewhere in the forces: Police Service in Northern Ireland (PSNI) last week [1]confirmed it unwittingly exposed a spreadsheet containing details of serving police officers; and this week [2]Cumbria constabulary said it mistakenly published the names, salaries and allowances for all officers and staff online.
Today in a joint statement, Norfolk and Suffolk constabularies – based in the east of England – say they "identified an issue relating to a very small percentage of responses to Freedom of Information Requests for crime statistics, issued between April 2021 and March 2022."
[3]
"A technical issue has led to some raw data belonging to the constabularies being included within the files produced in response to the FoI requests in question. The data was hidden from anyone opening the files, but it should not have been included.
[4]
[5]
"The data impacted was information held on a specific police system and related to crime reports. The data includes personal identifiable information on victims, witnesses, and suspects, as well as descriptions of offences. It related to a range of offences, including domestic incidents, sexual offences, assaults, thefts, and hate crime."
The constabularies say they have completed an analysis of the incidents, and have started to tell affected individuals about the impact to their personal data. "We will be notifying a total of 1,230 people whose data has been breached."
[6]
"We would like to apologise that this incident occurred, and we sincerely regret any concern that it may have caused the people of Norfolk and Suffolk," said Eamonn Bridger, assistant chief constable of Suffolk Police.
"I would like to reassure the public that procedures for handling FoI requests made to Norfolk and Suffolk constabularies are subject to continuous review to ensure that all data under the constabularies' control is properly protected."
So far, Norfolk and Suffolk police reckon that data has not been accessed by anyone outside of policing, nevertheless the UK's data watchdog, the Information Commissioner's Office, was notified of the leak.
[7]Northern Ireland police may have endangered its own officers by posting details online in error
[8]Criminal records office yanks web portal offline amid 'cyber security incident'
[9]Brit cops rapped over app that recorded 200k phone calls
[10]Police National Computer not pwned by Clop ransomware crims, insists Home Office
[11]Activist raided by police after downloading London property firm's 'confidential' meeting minutes from Google Search
Stephen Bonner, deputy commissioner at the ICO, said in a statement:
"The potential impact of a breach like this reminds us that data protection is about people. It's too soon to say what our investigation will find, but this breach – and all breaches – highlight just how important it is to have robust measures in place to protect personal information, especially when that data is so sensitive.
[12]
"We are currently investigating this breach and a separate breach reported to us in November 2022."
The latest incident pales into insignificance compared to the events in Northern Ireland, where [13]PSNI has now [14]confirmed that dissidents have accessed the data dump that identified 10,000 officers and staff, their units and locations. ®
Get our [15]Tech Resources
[1] https://www.theregister.com/2023/08/09/psni_data_breach/
[2] https://www.theregister.com/2023/08/14/cumbrian_police_accidentally_published_officer_details_online/?td=rt-3a
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNuhMUlE8pEjAHplsiC1GQAAA4A&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNuhMUlE8pEjAHplsiC1GQAAA4A&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNuhMUlE8pEjAHplsiC1GQAAA4A&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNuhMUlE8pEjAHplsiC1GQAAA4A&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2023/08/09/psni_data_breach/
[8] https://www.theregister.com/2023/04/06/acro_security_incident/
[9] https://www.theregister.com/2023/04/18/ico_surrey_sussex_police/
[10] https://www.theregister.com/2021/12/20/dacoll_ransomware_clop_pnc_claims/
[11] https://www.theregister.com/2021/08/10/police_raid_man_for_downloading_google_search_docs/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNuhMUlE8pEjAHplsiC1GQAAA4A&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2023/08/09/psni_data_breach/
[14] https://www.ft.com/content/7b29e72c-bcba-44a5-abb0-c9a57d35cb9c
[15] https://whitepapers.theregister.com/
Re: The data was hidden from anyone opening the files
It means the data was in an Excel file and was completely visible to anyone who spotted that the column numbers weren't sequential and then clicked on the 'Unhide' option.
Re: The data was hidden from anyone opening the files
Seems quite complicated.
You sure they just didn't change the text colour to white?
Re: The data was hidden from anyone opening the files
>to anyone who .... clicked on the 'Unhide' option.
So that would be a hacking charge
Isn't it seeing triple now?
I mean, first it was NI Police via a FOIA request, then Cumbrian Police via a FOIA request, and now Norfolk & Suffolk? That's three I count so far.
Looks like people are being lazy when replying to FOIA requests, or are not given the appropriate training to ensure FOIA requests don't leak personal data.
Re: Isn't it seeing triple now?
I'm tempted to submit an FOI request asking how many people at each police force deal with FOI requests, and see if the names of the specific clerical staff end up in there somewhere.
Re: Isn't it seeing triple now?
Quadruple. Norfolk and Suffolk are separate police forces.
Re: Isn't it seeing triple now?
"based in the east of England " is a bit of an odd phrase
I' would have used "cover their respective counties" but that might confuse LeftPondians, so could just say "In East Anglia"
Re: Isn't it seeing triple now?
I don't think it's a particularly odd phrase. Saying "their respective counties" is only meaningful if you know where Norfolk and Suffolk are. Likewise, referring to East Anglia" is only meaningful if you know where East Anglia is (and it's a stretch to imagine that someone knows where East Anglia is, but doesn't know that it's affectively a synonym for Norfolk & Suffolk)
Re: Isn't it seeing triple now?
East of England includes everywhere from Northumberland to Kent.
Re: Isn't it seeing triple now?
Well, no. East of England generally refers to Norfolk and Suffolk. At least on the weather forecast, which is all that matters.
Northumberland is in The North, and Kent is in The South East.
Also, I'm not sure why they lump Norfolk and Suffolk together and in Suffolk we don't tend to marry our siblings (apart from Shotley, which used to get cut off regularly by the sea - so not much else to do I guess?)
Re: Isn't it seeing triple now?
The official EU Region included Cambridgeshire, Bedfordshire and Hertfordshire as well.
I guess we can now define it however we like.
Taking back control (TM)!
Re: Isn't it seeing triple now?
Northumberland is in The North
Yes...and Manchester isn't.
(spoken as a Northumbrian)
Re: Isn't it seeing triple now?
"East of England generally refers to Norfolk and Suffolk. At least on the weather forecast, which is all that matters."
Context was post worrying about confusing Left-Pondians who won't be listening to UK weather forecasts. Taken literally by someone with no other context the East of England would literally* be anywhere from Northumberland to Kent inclusive.
* Literally literally.
Re: Isn't it seeing triple now?
Oh I'm American, I know where East Anglia is! It's just north of Nambia, right?
Re: Isn't it seeing triple now?
East Anglia is obviously to the East of West Anglia!!
Re: Isn't it seeing triple now?
"or are not given the appropriate training to ensure FOIA requests don't leak personal data"
More likely this. A further possible cause is someone being handed the job just before the deadline and not having time to do the job.
Whatever the factors there seems to be a collective lack of quality in this area. Perhaps the forces could join together to set up a central, properly staffed office to which it would be mandatory to send responses to review and release.
Re: Isn't it seeing triple now?
>join together to set up a central, properly staffed office
But that would allow the enemy access to their data
Captain paranoid
Certain actors attempting to discredit FOI?
Re: Captain paranoid
But, and this is often ignored, there are huge issues dealing with FOIA requests where organisations will not be robust enough in responding to the serial requesters and vexatious requests.
I would surmise that teh actual request may have come from the same source. There are people out there who do nothing but send out request after request.
I am not excusing the mistakes but having been on the receiving end of some of these:
An inventory of all our network equipment, manufacturer, model, purchase date
The same for all storage and servers
The square meter area occupied for teaching space compared to admin.
The list goes on.
Management and CIOs are scared to say no so people run round sorting all this crap out.
FOIA has it's place however it is just being abused and most of the requests are absolutely nothing to do with the original concepts when it was first setup.
Re: Captain paranoid
Management and CIOs are scared to say no
I'm not particularly up on this stuff, so it's a genuine question... what happens if they do say no? Surely there's a mechanism in the Act to tell people to do one if it's an unreasonable request?
Re: Captain paranoid
The ICO has the details [1]here .
Of course, the UK government has gone out of its way to [2]exploit every possible loophole in order to frustrate otherwise admissible requests.
[1] https://ico.org.uk/for-organisations/foi-eir-and-access-to-information/guide-to-freedom-of-information/refusing-a-request/
[2] https://www.opendemocracy.net/en/freedom-of-information/uk-government-running-orwellian-unit-to-block-release-of-sensitive-information/
Re: Captain paranoid
Nice, thanks for the links! Interesting reading.
Re: Captain paranoid
"Surely there's a mechanism in the Act to tell people to do one if it's an unreasonable request?"
Yes, absolutely, and also if it would cost too much.
The latest blunder follows a litany of recent errors elsewhere
Somebody must be sat in an office somewhere trying desperately to think up a good excuse for all this.....
"Following our investigation, we have concluded that no actual errors were made, the data was just going away on it's usual August Summer holidays"
Where's next?
I suspect that Scotland will be next. Their very existence a a single item betrays huge political fiddling. It will then be something else that they can blame the former 1st minister for.
Re: Where's next?
Scotland has already had a breech this week, they accidentally published all the personal details of all adopted and fostered children in Scotland.
Re: Where's next?
"Scotland has already had a breech this week"
No kilt?
The data was hidden from anyone opening the files
What does that even mean ?