Man arrested in Northern Ireland police data leak as more incidents come to light
- Reference: 1692273839
- News link: https://www.theregister.co.uk/2023/08/17/man_arrested_in_ni_police/
- Source link:
The information was leaked when police posted a [1]spreadsheet online listing the surnames and initials of 10,000 serving officers in the Police Service of Northern Ireland (PSNI), plus civilian staff members. The info had been published in error in response to a Freedom of Information (FoI) request, according to the PSNI.
The force has now said that a 39-year-old man was arrested on suspicion of Collection of Information likely to be useful to Terrorists, following a search in Lurgan, County Armagh, on August 16.
[2]
This offence appears to date to the [3]Terrorism Act 2000 , which states that a person commits an offence if they collect or make a record of "information of a kind likely to be useful to a person committing or preparing an act of terrorism." It includes viewing, or otherwise accessing by means of the internet, a document or record containing information of that kind.
[4]
[5]
The unnamed man was questioned by detectives who were said to be "investigating criminality linked to last week's freedom of information data breach," but has now been released on bail to allow for further inquiries, the PSNI informed us.
However, the force declined to say if the arrested man was known or suspected to have any links with terrorist organizations.
[6]
In a [7]statement , Detective Chief Superintendent Andy Hill said the force was "working tirelessly" to address the risk posed to officers and staff following the data leak, and that the arrest was just one piece of a large scale operation.
"We will continue in our efforts to disrupt criminal activity associated with this freedom of information data breach and to keep communities, and our officers and staff who serve them, safe," he added.
PSNI Chief Constable Simon Byrne had already stated he was confident that dissident republican groups, which have a history of targeting police officers, had obtained access to the data, which listed the rank or grade of all police staff, plus the location where they worked and in which department.
[8]
Details of a further data leak were also disclosed after the news of the spreadsheet became public. According to the [9]BBC , documents plus a police issue laptop and radio were said to have been stolen from a private vehicle in the Newtownabbey area of County Antrim on July 6. The documents were understood to list details of 200 officers and staff.
Earlier this week, it was revealed that [10]Cumbria Constabulary had inadvertently published the names and salaries of all its officers and staff online earlier this year. Cumbria cops said the information was removed as soon as its publication was discovered, but did not indicate how long it had been online.
Also this week, [11]Norfolk and Suffolk constabularies disclosed that information relating to 1,230 people had inadvertently been included in responses to some FOI requests for crime statistics issued between April 2021 and March 2022.
[12]You're not seeing double – yet another UK copshop is confessing to a data leak
[13]Cumbrian Police accidentally publish all officers' details online
[14]Electoral Commission had internet-facing server with unpatched vuln
[15]Northern Ireland police may have endangered its own officers by posting details online in error
The data included personal identifiable information on victims, witnesses, and suspects, as well as descriptions of offences. The force said the data in question was hidden from anyone opening the files, but it should not have been included.
It appears that the UK's data watchdog, the Information Commissioner's Office, is likely to be very busy investigating all of the recent data exposure incidents. PSNI Chief constable Byrne had already said he was working on the assumption that his force would be liable to penalties from the ICO or from officers bringing legal claims about the disclosure of their personal data. ®
Get our [16]Tech Resources
[1] https://www.theregister.com/2023/08/09/psni_data_breach/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZN5ELrGGH111dap-7RD8QgAAA88&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.legislation.gov.uk/ukpga/2000/11/section/58#commentary-key-958aed83b6f6c7041cad6f7da254b116
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZN5ELrGGH111dap-7RD8QgAAA88&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZN5ELrGGH111dap-7RD8QgAAA88&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZN5ELrGGH111dap-7RD8QgAAA88&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.psni.police.uk/latest-news/search-and-arrest-made-detectives-investigating-criminality-linked-last-weeks-data
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZN5ELrGGH111dap-7RD8QgAAA88&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.bbc.co.uk/news/uk-northern-ireland-66454684
[10] https://www.theregister.com/2023/08/14/cumbrian_police_accidentally_published_officer_details_online/
[11] https://www.theregister.com/2023/08/15/norfolk_and_suffolk_police_data_breach/
[12] https://www.theregister.com/2023/08/15/norfolk_and_suffolk_police_data_breach/
[13] https://www.theregister.com/2023/08/14/cumbrian_police_accidentally_published_officer_details_online/
[14] https://www.theregister.com/2023/08/11/electoral_commission_vulnerability/
[15] https://www.theregister.com/2023/08/09/psni_data_breach/
[16] https://whitepapers.theregister.com/
Re: I understand why but it's a bit of a bullshit charge
Only today in England, Liverpool Police have had a kicking for trying to prosecute a poor sod they sent classified information to by mistake.
Re: I understand why but it's a bit of a bullshit charge
Yes, and no.
For instance, I have an interest in military history and have a number of books sitting on my bookshelves about quite nasty improvised weapons the home guard deployed during WW2, and a instruction manual on practical methods for guerrilla warfare published during WW2. (both came from Waterstones; strangely...)
While owning those is absolutely legal, were I to develop links with a terrorist organisation then I would expect that my ownership of those would probably (and quite rightly) considered to be materials useful to terrorism which is an offense in the UK. This is easier to prosecute than membership of a proscribed organisation since terrorist organisations rarely issue convenient membership cards, and their members do tend to lie about their membership of that sort of group.
In the same way, it's [1]well known that the IRA was funded and lavishly equipped by the Soviet Union to cause problems in Britain during the cold war; which is where the IRA got their funding, plastic explosives, RPG's, HMG's and AK's from. After decades of peace, after Russia invaded Ukraine elements of the real FSB IRA hunted down and shot an off duty police officer 6 months ago while he was coaching kids at a club.
In that context i'd suggest that anybody with links to the Real IRA (or the Real Russians) who downloaded a list of police officers and then say the electoral registrar with a list of names and addresses and started cross referencing them could probably expect that while owning both sets of public information is entirely legal, the combination of both along with their associations would be quite enough to justify a forensic examination of their entire life and their contacts under anti terrorism legislation while they are safely incarcerated.
And frankly, I don't think that that would particularly bother many people in England, Wales, Scotland or either the Northern Ireland, or the Republic of Ireland since I doubt that many people think that political violence is any kind of answer to anything. The investigation would be as fair as anything conducted by human beings is capable of being, so if they were innocent then they would in all likelihood be found innocent by the criminal justice system. (We don't do "plead guilty or else" or any other form of plea bargaining system on this side of the pond)
[1] https://en.wikipedia.org/wiki/Irish_Republican_Army%E2%80%93Soviet_Union_collaboration
We don't do "plead guilty or else"
"The investigation would be as fair as anything conducted by human beings is capable of being, so if they were innocent then they would in all likelihood be found innocent by the criminal justice system"
While I appreciate your faith in the British justice system, I can think of a few occasions during the relatively recent past when innocent Irish people got locked up: Birmingham Six, Guildford Four and Maguire Seven, Winchester Three, etc.
Re: I understand why but it's a bit of a bullshit charge
While owning those is absolutely legal
I'd advise a little caution. You're reliant on a court agreeing you have a 'reasonable excuse' for possessing them. Your membership of an organisation doesn't in any way affect the fact of them being likely to be useful to terrorists. They either are or they aren't.
While there's a fair amount of precedent at this point, juries tend to be generous with the excuse definition, and the CPS doesn't waste resources against people they don't actually want in prison (perhaps for some other reason), the burden of proof is still on you to explain your possession. That's a bit different from something being absolutely legal. Waterstones' employees have the very reasonable excuse that they're selling the books to buyers who have a responsibility to ensure they in turn have a reasonable excuse. Hopefully you do have a fair number of other military history books, records of visiting exhibitions or association with other enthusiasts and so on to back up your academic interest.
Incidentally if this N.Ireland arrest is related to the spreadsheet leak it's likely to be one of the slightly different (and arguably less bullshit) offences which specifically criminalises information about police officers. For example section 58A presumably makes it an offence to even ask someone to give you this spreadsheet:
https://www.legislation.gov.uk/ukpga/2000/11/section/58A
"A person commits an offence who—
(a)elicits or attempts to elicit information about an individual who is or has been—
(i)a member of Her Majesty's forces,
(ii)a member of any of the intelligence services, or
(iii)a constable,
which is of a kind likely to be useful to a person committing or preparing an act of terrorism, or
(b)publishes or communicates any such information."
(It would also criminalise the original leak if it were intentional, but that doesn't appear to the case)
Re: I understand why but it's a bit of a bullshit charge
"In the same way, it's well known that the IRA was funded and lavishly equipped by the Soviet Union to cause problems in Britain during the cold war; which is where the IRA got their funding, plastic explosives, RPG's, HMG's and AK's from."
According to the document you linked to it mentions only a single shipment (this is "lavishly equipped"?) during the Cold War and does not mention any funds being provided during that period.
Contrast this with multiple large Libyan shipments and funding from (mainly Irish-American) US citizens during the course of The Troubles...
Also "the IRA" - which one are you referring to? Official IRA? Provisional IRA? Continuity IRA? Real IRA? New IRA? I can't believe it's not the IRA?
Re: I understand why but it's a bit of a bullshit charge
Yes, this is just scapegoatism, to divert attention away from the real problem.
Newsflash
The current IC will do absolutely nothing, zilch, nada.
He will issue a stern telling off as he can't be bothered to enforce the legislation and makes up punishments on a whim
So, arrested for accessing published information ?
Well done The Plod. You goofed, and now you're blaming anyone who looks at your goof.
I'm sure the terrorist charges were welcome.
I think Collection of Terrorist Information should be mirrored by a Publication of Terrorist Information.
Then we'd see how many numbskulls remained to goof like that.
Re: So, arrested for accessing published information ?
I'd like to see what happens when the lawyer gets involved and points out the PSNI were acting as Agent Provocateur with the release of information. Because surely they're not that incompetent that they'd release information like this by just a pure mistake?
Re: So, arrested for accessing published information ?
THAT's your username and you're saying they're the agents provocateur? :D
Every other police service under the management of the UK Crown seem to be leaking left right and centre, why should the RUC PSNI be different?
Re: So, arrested for accessing published information ?
According to my 10-minute bout of research into the Terrorism Act 2000, the plod might be in contravention of section 58 (1) (a) concerning making a record of information which may be useful to terrorists.
https://www.legislation.gov.uk/ukpga/2000/11/section/58
Perhaps the CPS might take a view on that as making a record must include publishing information on a website.
We cocked up...
so we are desperately trying to find a scapegoat to divert attention away from us!
Publicly available data
Don’t look Ethel
Too late, she looked.
2 other NI public bodies receive ICO reprimand
Around the same time as the PSNI's 2 data leaks the ICO issued reprimands to 2 other NI public bodies regarding data leaks that occurred in 2020 and 2021:
https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2023/08/ico-warns-of-email-data-breach-risk-as-it-issues-two-reprimands/
Unlike the PSNI "big leak" which seems to have been due to that common mistake of "publishing an Excel spreadsheet without first removing additional sheets, that contain the source data, from it" these other 2 leaks were due to that other common data leak chestnut of "putting email recipients in the To or CC fields instead of BCC".
Perhaps like the OWASP Top 10 list we also need a GDPR Top 5 list of the most common causes of personal data breaches?
I won't be surprised if the ICO ends up only issuing a reprimand to the PSNI - it is now the ICO's policy to issue reprimands rather than fines to public bodies.
Not encrypted?
Encryption is standard for many companies. As it should be with police officers laptops. The current trend is going so far to NOT store recovery information (Bitlocker Recovery key as well known example) anywhere so the data cannot be decrypted by design and is considered safe. Losing the data on the Laptop is less a problem than an company admin which can access all recovery keys at once and possibly sell those somewhere.
Re: Not encrypted?
"Encryption is standard for many companies. As it should be with police officers laptops."
In the case of the "2nd" PSNI incident the problem does not appear to have been regarding the stolen laptop (which I assume was encrypted) but rather with the paper documents stolen at the same time which contained the details of 200 members of staff
I understand why but it's a bit of a bullshit charge
The PSNI published this information. In relation to a Freedom of Information request.
They are now charging someone with copying and passing on the information they published freely.
Anywhere else but Northern Ireland this would be a case for a civil liberties countersuit.
If the person charged had other offenses, such as membership of a terrorist organisation, then charge them with those.