Home of the world's longest pleasure pier joins public sector leak club
- Reference: 1699268532
- News link: https://www.theregister.co.uk/2023/11/06/southend_council_foi_leak/
- Source link:
The data breach occurred as a result of a botched response to a request made under the Freedom of Information Act 2000 (FoI). The council uploaded a spreadsheet of what it thought contained solely anonymized job roles and structure data.
It later discovered that if the spreadsheet was "interrogated," personal and special category data of all current and former council staff as of March 31 could be viewed.
[1]
The document was initially uploaded on May 17, and was locked with permissions set to read-only. The council became aware of the accidental data exposure on October 27.
[2]
[3]
In total, more than 2,000 individuals were affected: 1,854 current staff and 276 former council workers were affected, as well as an additional 169 office holders and canvassers, and 55 councilors and co-opted members.
Co-opted members are not official councilors but serve as elected independent members of council committees.
[4]
The data exposed included names, addresses, national insurance numbers, pension scheme details, salaries, and equal opportunities data.
As a result, the council has self-reported to the Information Commissioner's Office (ICO).
"We have issued an advisory notice to public authorities calling for an immediate end to the use of original source Excel spreadsheets when responding publicly to FoI requests," an ICO spokesperson told The Register. "This follows a number of recent data breaches where personal information was inadvertently included in spreadsheets that were shared as part of a FoI response.
[5]
"Public authorities should be putting robust measures in place to protect personal data when responding to information access requests, and to reassure the people they serve, and their staff, that their information is in safe hands.
"Southend-on-Sea Council has made us aware of an incident and we are assessing the information provided."
Council leader Tony Cox extended the organization's apologies in a statement.
"We have immediately begun an investigation to understand how this happened and I sincerely apologize to those affected on behalf of the organization," he said.
"We have also taken immediate actions, including starting to investigate how this happened, undertaking an initial assessment to understand the potential risk to staff and whether the data could be used in a harmful way, providing advice and support to all staff affected, and stopping the use of Excel spreadsheets in our FoI responses. We are also reviewing our FoI protocols to ensure this cannot happen again."
[6]Okta tells 5,000 of its own staff that their data was accessed in third-party breach
[7]Seiko watches 60K personal data records tick away in BlackCat ransomware heist
[8]Casio keyed up after data loss hits customers in 149 countries
[9]530K people's info feared stolen from cloud PC gaming biz Shadow
The incident follows a spate of data breaches in the UK and Ireland's public sector in recent weeks. The [10]Police Service of Northern Ireland (PSNI) , as well as [11]Norfolk and Suffolk police forces , both fell foul of data protection standards during their respective FoI-related exposures.
In August, Cumbria Police [12]published the names and salaries of all its officers and staffers. The ICO decided at the time that no further action was needed other than to remind of what is expected in terms of data protection measures.
Later that month London's Metropolitan Police [13]exposed details of 47,000 officers as a result of a third-party breach.
Greater Manchester Police's [14]incident was also caused by a breach at a third-party supplier of ID badges.
Most recently, more than half a million records related to vehicle seizures were [15]exposed by an unsecured database managed by an unnamed Limerick contractor in Ireland. The data breach affected civilians and members of the Irish National Police (An Garda Síochána). ®
Get our [16]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZUkbsr29HKryY7sPQnNGHAAAAFM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUkbsr29HKryY7sPQnNGHAAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUkbsr29HKryY7sPQnNGHAAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUkbsr29HKryY7sPQnNGHAAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUkbsr29HKryY7sPQnNGHAAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/11/02/okta_staff_personal_data/
[7] https://www.theregister.com/2023/10/25/seiko_august_breach_update/
[8] https://www.theregister.com/2023/10/19/casio_data_theft/
[9] https://www.theregister.com/2023/10/13/shadow_data_theft/
[10] https://www.theregister.com/2023/08/09/psni_data_breach/
[11] https://www.theregister.com/2023/08/15/norfolk_and_suffolk_police_data_breach/
[12] https://www.theregister.com/2023/08/14/cumbrian_police_accidentally_published_officer_details_online/
[13] https://www.theregister.com/2023/08/29/met_police_data_breach/
[14] https://www.theregister.com/2023/09/15/greater_manchester_police_breach_demonstrates/
[15] https://www.theregister.com/2023/10/24/irish_national_police_leak/
[16] https://whitepapers.theregister.com/
In the olden days..
I understand that large tables of data used to be stored by something called a "database", and that subsets of data could be exported to interested parties without exposing the entire database, with a "query" or a " report".
This post feels too short, so let me add a footer
-- Bring Dabbsy Back --
Re: Excel and FoI basics
And the resulting data should be in a CSV file, both to avoid proprietary formats and to exclude any misused formatting.
Re: Excel and FoI basics
For which Oracle would only charge twice their normal consulting rate. But because it's a legal FOI the offshore minimum wage workers should be paid charged at the same hourly rate as lawyers
Re: Excel and FoI basics
It's the one sole reason for which I tolerate CSV.
No fancy hidden data, just a text-readable file that you can inspect and search for any private data if necessary.
We need a kind of "PDF" standard for data export (but, again, without the possibility of revealing data hidden behind poor censorship attempts, etc.).
Something like a single SQLite database table with no fancy features, or similar. Or Firebird. Same kind of program.
Re: Excel and FoI basics
Plain text. That could cover CSV.
No PDF. No SQLite or other database. I have nothing against either in their place but this is not their place.
The standard you are looking for is plain text where everything is visible for inspection.
Re: Excel and FoI basics
"that, should be extracted into a new document..."
And that new document should be a plain text file.
"...that gets verified"
Verified by someone who knows the difference between a plain text file and a WP document or spreadsheet.
I might stretch a point to allow CSV.
" We have immediately begun an investigation to understand how this happened "
An investigation that, presumably, will completely exonerate the managers and politicians who for years have neglected staff training, and point the finger squarely at the hapless drones.
Sigh.
Except the LA will have to have 95% of users complete training annually to access NHS data for social care purposes.
Its more a case of the people sending the response being understaffed and being under pressure to meet service standards by getting the responses out as quickly as possible and the team sending the data to them being too lazy to do the prep work to extract the information
It's not necessarily lack of staff training that's the problem. The staff training might have included extracting data into a spreadsheet. The underlying problem is more likely to be lack of a proper procedure as in Mike 137's post and insistence on a format that precludes any hidden content that might escape initial inspection.
Far too dangerous
Clearly anyone from junior management and above should not be allowed anywhere near the internet, and the rest of the workfarce should only be permitted limited access under the watchful gaze of someone with at least two communicating neurons.
P.S. workfarce was a typo, but it fits rather well!
So :
The data exposed included names, addresses, national insurance numbers, pension scheme details, salaries, and equal opportunities data.
everything anyone would ever need for a permanent ongoing identity theft. In fact there is so much there it's entirely possible a fraudster could take control of someones accounts and they could never ever recover them. Which I've known happen more than once.
Re: So :
Not really.
Your NI number isn't privileged and nothing should hang off it (unless people are being absolutely incompetent).
Your name and address are a matter of public record, easily discovered for any given individual - you give that to Amazon or everyone that you ever receive a letter from, for example.
Pension scheme - yeah, maybe some slight phishing possibility there but nothing really major.
Salary? Nope. Horrible personal data to have leaked but not a security issue of accessing anything (nobody genuine is going to ask you to enter your salary to gain access to a website, for example).
Same for equal opportunities data.
Any place that lets the above information take over an account without checking is utterly incompetent, and probably failing their own GDPR to be honest.
What I don't see in that list are passwords, account numbers, security questions, etc. that would actually be required to directly do any harm.
It's actually quite a low-level compromise, with the exception of the salaries.
P.S. your employer knows all the above, anyone who works in the accounts or payroll department, anyone who works in the HR department, as do all of your previous employers up to a given point in time.
Re: So :
Putting it altogether in one place is still a bad thing. And although NI number shouldn't be used for anything other than NI purposes it is, widely, especially by financial institutions.
Were Capita involved?
That's what we all want to know.
Re: Were Capita involved?
In a very real sense, aren't they always ?
They are shortening their pier...
...to enable them to take a long walk along/off it.
A good thing in a way. It didn't include information about the wider public and, given the personal involvement, will encourage them to be more careful in the future when it might be the wider public at risk.
Experience is a dear teacher but there are those that will learn by no other.
Excel and FoI basics
Once again (oh, so often), hiding columns in Excel doesn't prevent access to the data they hold. And making the file 'read only' doesn't prevent the content being read. No master spreadsheet (or for that matter any primary document) should ever be sent out in response to an FoI request. The specific data requested, and no more than that, should be extracted into a new document that gets verified for scope against the request before it's issued.
But of course that involves effort, attention and judgement, all of which seem to be in short supply, and not just in local government..