News: 1693308913

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

More UK cops' names and photos exposed in supplier breach

(2023/08/29)


London's Metropolitan Police has said a third-party data breach exposed staff and officers' names, ranks, photos, vetting levels, and salary information.

In a statement posted on the cops' website, the force said miscreants broke into a supplier's IT system, and used that unauthorized access to steal personnel information. The supplier did not, however, store police addresses, phone numbers or financial account details so it appears that data remains secure.

"Security measures have been taken by the MPS as a result of this report," the [1]statement said, adding that the UK National Crime Agency and Information Commissioner's Office have both been made aware of the breach.

[2]

The Met did not immediately respond to The Register 's questions about the breach, including the identity of the supplier, how many individuals' details were exposed, who was responsible for the intrusion, and what security measures the agency undertook as a result of the compromised IT system.

[3]

[4]

According to The Sun, which first [5]reported on the breach , all 47,000 staff members and police officers – including senior officials, undercover and counter-terrorism cops, and officers assigned to guard the royal family – were exposed.

"Anyone using these details to produce a warrant card or pass could gain access to a police station or secure area," former Met commander John O'Connor told the newspaper.

[6]

"There is also a huge concern that photographs of police on undercover units, surveillance or in sensitive areas like counter-terrorism could fall into the wrong hands," he added. "This data breach has put the safety of police at risk."

[7]Man arrested in Northern Ireland police data leak as more incidents come to light

[8]You're not seeing double – yet another UK copshop is confessing to a data leak

[9]Electoral Commission had internet-facing server with unpatched vuln

[10]FBI: Who was going around hijacking Barracuda email boxes? China, probably

The Met data breach follows a handful of other leaks at UK cop shops over the past few weeks.

On August 16, a man was [11]arrested in Northern Ireland after police posted a [12]spreadsheet online that listed last names and initials of 10,000 serving officers in the Police Service of Northern Ireland (PSNI), plus civilian staff members.

According to the PSNI, the data had been mistakenly published in response to a Freedom of Information request, and the man was arrested on "suspicion of collection of information likely to be useful to terrorists."

That same week, England's [13]Norfolk and Suffolk police also copped to a leak. This one, blamed on a "technical issue," resulted in raw data about crime reports being mistakenly included in Freedom of Information responses to crime statistic requests.

[14]

And just days before that security blunder, [15]Cumbria police accidentally published the names, salaries, and allowances for all staff and officers online. ®

Get our [16]Tech Resources



[1] https://news.met.police.uk/news/statement-re-unauthorised-access-to-it-system-of-a-met-supplier-471333

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZO4WJZvfLSyJDQIXBpJFGwAAAhc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZO4WJZvfLSyJDQIXBpJFGwAAAhc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZO4WJZvfLSyJDQIXBpJFGwAAAhc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.thesun.co.uk/news/23668982/metropolitan-police-hacked-security-breach/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZO4WJZvfLSyJDQIXBpJFGwAAAhc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/08/17/man_arrested_in_ni_police/

[8] https://www.theregister.com/2023/08/15/norfolk_and_suffolk_police_data_breach/

[9] https://www.theregister.com/2023/08/11/electoral_commission_vulnerability/

[10] https://www.theregister.com/2023/08/25/fbi_china_barracuda/

[11] https://www.theregister.com/2023/08/17/man_arrested_in_ni_police/

[12] https://www.theregister.com/2023/08/09/psni_data_breach/

[13] https://www.theregister.com/2023/08/15/norfolk_and_suffolk_police_data_breach/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZO4WJZvfLSyJDQIXBpJFGwAAAhc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://www.theregister.com/2023/08/14/cumbrian_police_accidentally_published_officer_details_online/?td=rt-3a

[16] https://whitepapers.theregister.com/



"Security measures have been taken by the MPS as a result of this report," the statement said

Mike 137

Always after the data breach. The only viable security is proactive security -- making your infrastructure the hardest possible nut to crack commensurate with the value/sensitivity of the information to be protected -- before it's been breached .

The big problems that prevent this are [1] the up front cost, which usually seems unnecessary because "nothing's happened yet", [2] the utter uselessness of current common practice in risk assessment, which typically causes assessment results to be meaningless, [3] a fundamental misapprehension that 'policies' automatically drive behaviours, [4] an almost complete lack of adequate training for staff at all levels, right up to the executive, who frequently get exempted from the (typically useless) so-called 'training' provided.

Until these deficiencies are fixed, there'll be no such thing as genuine infosec, so the adversary will usually win.

Re: "Security measures have been taken by the MPS as a result of this report," the statement said

alain williams

We have not yet been told "lessons will be learned", after which we will all be able to relax safe in the knowledge that it will never happen again -- not!

Re: "Security measures have been taken by the MPS as a result of this report," the statement said

Doctor Syntax

Lessons should be learned from mistakes but it's best if you can learn them from other people's mistakes.

cantankerous swineherd

nothing to hide, nothing to fear.

Headley_Grange

Since you don't post with your real name I wonder what you've got to hide.

IR35

elsergiovolador

After IR35 changes British businesses lost access to skilled workers - they retired early or moved on.

The IT incidents will be piling on...

Re: IR35

IGotOut

So contractors never fucked up? New one on me.

Re: IR35

elsergiovolador

We didn't hear of as many incidents prior to the changes to legislation.

If contractor efs up, their business is in a pickle if they don't have adequate insurance, so they must be extra sure they don't ef up.

Now hiring a zero hour IT deemed employee worker doesn't come with such reassurances.

Re: IR35

Headley_Grange

"We didn't hear of as many incidents prior to the changes to legislation."

Maybe the reporting restrictions were less prescriptive or there are more bad actors out there than there used to be.

sitta_europea

If they're that careless with information about their own staff, what must it be like in the complaints department?

elsergiovolador

Maybe complaints are stored securely in /dev/null ?

heyrick

The rozzers have a complaints department? Would that be the dark room at the end of a corridor lined with snarling men holding their truncheons in a menacing manner?

Red Or Zed

Of course not, that's completely ridiculous!

It'll be just down these stairs.

Mind you don't trip...

Anonymous Coward

In a statement posted on the cops' website, the force said miscreants broke into a supplier's IT system, and used that unauthorized access to steal personnel information.

Tell me that you entrusted the job to Capita without telling me that you entrusted the job to Capita

I can only hope

Lis

that the locks on prison cells are more secure than the locks on the data

QOTD:
"It's been Monday all week today."