Britain's Ministry of Defence fined £350K over Afghan interpreter BCC email blunder
- Reference: 1702459809
- News link: https://www.theregister.co.uk/2023/12/13/mod_bcc_email_fine/
- Source link:
The potentially [1]life-or-death breach happened in autumn 2021 following the complete withdrawal of UK and US troops in the summer, leaving a power vacuum that was filled again by the militant Pashtun national organization.
The Taliban had embarked on a campaign to seek out and punish any Afghans helping Western military. Some interpreters were reportedly murdered and many feared for their lives.
[2]
The offending BCC email was sent on September 20, 2021, by the UK's Afghan Relocations and Assistance Policy (ARAP), the unit in charge of assisting the relocation of citizens who worked for or with the UK government in Afghanistan.
[3]
[4]
The distribution list included Afghan nationals that were eligible for evacuation. The email urged the interpreters, somewhat ironically, not to put themselves or their families in danger. Personal information of 245 applicants was inadvertently exposed, and the email addresses could be seen by all with 55 having their thumbnail pic associated with the email account.
Two people even replied all to the entire list of recipients and one of them had provided their location.
[5]
"The data disclosed, should it have fallen into the hands of the Taliban, could have resulted in a threat to life," said the ICO today.
Recipients of the BCC email were asked to delete the email, change their email address, and tell the ARAP crew of their new contact details via a secure channel.
"Staff joining the ARAP team had to rely on the MoD's broader email policy and were not given specific guidance about the security risks of sending group emails when communicating sensitive information," the ICO said.
[6]
The MoD subsequently ran an internal investigation on the events, urging ARAP to update policies and processes – including asking for a second pair of eyes for cross checking purposes to look over emails that were being sent to multiple external recipients.
"This deeply regrettable data breach let down those to whom our country owes so much," said John Edwards, UK Information Commissioner. "This was a particularly egregious breach of the obligation of security owed to these people, thus warranting the financial penalty my office imposes today."
"Applying the highest standards of data protection is not an optional extra – it is a must, whatever the circumstances. As we have seen here, the consequences of data breaches could be life-threatening," Edwards added.
[7]Foreign Office IT chaos: Shocking testimony reveals poor tech support hindered Afghan evac attempts
[8]DoJ: Ex-soldier tried to pass secrets to China after seeking a 'subreddit about spy stuff'
[9]US think tank says China would probably lose if it tries to invade Taiwan
[10]UK Ministry of Defence takes recruitment system offline, confirms data leak
The MoD was found to have broken UK GDPR by failing to have sufficient safeguards in place to prevent the issues. The ARAP team had relied on BCC, which "carries a significant risk of human error," the ICO said
The ICO today advised the MoD to use bulk email services, mail merge or secure data transfer services when dispatching sensitive personal data electronically.
In a statement to The Reg , a spokesperson at the MoD said: "We have cooperated extensively with the ICO throughout their investigation to ensure a prompt resolution, and we recognise the severity of what has happened. We fully acknowledge today's ruling and apologise to those affected.
"We have introduced a number of measures to act on the ICO's recommendations and will share further details on these measures in due course."
A fine of £1 million was reduced to £700,000, the ICO said, reflecting the corrective actions taken the Department, and then halved under the Public Sector Approach, which is designed to act as a deterrent to data breaches to ensure fresh training and policies are put in place.
The MoD's internal probe into the September 20 events also found [11]another instance that same month involving BCC blunders.
Will Richmond-Coggan, partner and head of data breach litigation at Freeths, told us:
"The ICO’s willingness to impose a significant fine, despite its recent policy of only issuing reprimands in relation to public sector breaches, underscores the gravity of this incident.
"The more sensitive the information, the more stringent the measures that need to be in place to protect it. Here, the MoD has acknowledged that the risks around disclosure were potentially matters of life and death.
"In my view, this incident serves as a vital reminder to organisations of all shapes and sizes to keep processes for securing and sharing data under review, and to be ready to implement additional safeguards where merited by the sensitivity of specific data." ®
Get our [12]Tech Resources
[1] https://www.theregister.com/2021/09/21/mod_email_fail_afghan_interpreters_data/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXmO2HqefnAmQfGrrsRxUQAAAAg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXmO2HqefnAmQfGrrsRxUQAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXmO2HqefnAmQfGrrsRxUQAAAAg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXmO2HqefnAmQfGrrsRxUQAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXmO2HqefnAmQfGrrsRxUQAAAAg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2021/12/07/foreign_office_it_chaos_testimony/
[8] https://www.theregister.com/2023/10/09/doj_soldier_secrets_china/
[9] https://www.theregister.com/2023/01/12/china_taiwan_wargame_scenarios/
[10] https://www.theregister.com/2022/03/24/ministry_of_defence/
[11] https://www.theregister.com/2021/09/23/afghan_email_fail_ministry_defence/
[12] https://whitepapers.theregister.com/
So BCC not good anymore ?
I fail to see how using BCC is any more subject to human error than bulk email. It's when you're not using BCC and bunging everyone into SendTo that things are worse. That is what must have happened here. Instead of using BCC, they sent the mail out with addresses in the SendTo and probably got people killed. That fact will be on their conscience forever, fine or not.
And who are you going to fine for the brilliant decision of not bringing along those fine Afghan people who helped you and stood by you but didn't have the proper paperwork done in the madness of a hasty withdrawal ? You could have gotten them out and bothered with the paperwork later, when they were safe, but noooo. You don't have your paperwork ? We thank you for your service during all these years, and wish you good luck with the Taliban. Next !
Government agency fines government agency. We are all fined then reimbursed! Wow. Was nobody fired?
Was nobody fired?
No, just fined.
It's instructive to compare this and the PSNI breaches with https://www.theregister.com/2023/12/12/us_air_force_discord_leaker/
I can guess which one is going to lead to things being tightened up in practice.
How exactly does the government fining itself achieve anything?
Surely incompetence of this order demands that heads roll; and new leadership brought in to address the underlying issues.
Otherwise one can only expect a continuation of malpractice.