News: 1702634346

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

To BCC or not to BCC – that is the question data watchdog wants answered

(2023/12/15)


A data regulator has reminded companies they need to take care while writing emails to avoid unintentionally blurting out personal data.

Unsurprisingly, much of the UK's Information Commissioner's Office (ICO) [1]guidance comes down to the correct use of address fields for recipients and considering the content of an email before hitting the bulk send button.

The ICO warned companies that staff need training on how to properly use the Carbon Copy (CC) and Blind Carbon Copy (BCC) fields.

[2]

The watchdog said it had "seen hundreds of personal data breach reports where a sender has misused the 'BCC' field."

Britain's Ministry of Defence fined £350K over Afghan interpreter BCC email blunder [3]READ MORE

The misuse ranges from simply forgetting to use the BCC field to placing confidential information in emails that aren't encrypted and can be viewed as they flow through servers on their way to their destination.

As a reminder for any Reg readers living under rocks, using the "BCC" field means that recipients cannot see each other's email addresses - useful for a bulk email with a large mailing list. "CC" means the email addresses can be seen, which can be useful in ensuring a recipient is aware of who else is getting the same email.

[4]

[5]

The ICO cited two case studies where the "To" or "CC" fields were used erroneously instead of "BCC." In the first, an NHS Trust manually copied patients' email addresses and pasted them into the "To" field to send a bulk email about an art competition. While the email didn't contain confidential information, the presence of all those email addresses in the "cc" field meant recipients could identify active patients of the trust. The health body was fined for the error.

In the second case study a charity performed an incomplete migration to a secure email platform. While they waited for the job to complete, emails still needed to be sent. For one of these emails, a staff member erroneously added addresses to the "CC" field manually. Email addresses were, therefore, visible to all recipients. The email was an agenda for an event and was sent to [6]105 members of an HIV advisory board .

[7]

The ICO noted: "65 of the 105 email addresses clearly identified recipients, with two recipients contacting the charity to highlight the incident."

Email is decades old, and it is unsettling that people are still making errors in this way. Hence the ICO's reminder that organizations need to be aware of best practices and take a risk-based approach to email.

[8]NHS Digital exposes hundreds of email addresses after BCC blunder copies in entire invite list to 'Let's talk cyber' event

[9]UK Ministry of Defence apologises after Afghan interpreters' personal data exposed in email blunder

[10]Reply-All storm flares as email announcing privacy policy puts 500 addresses in the 'To' field, not 'BCC'

[11]Brit housing association blabs 3,500 folks' sexual orientation, ethnicity in email blunder

[12]150 infosec bods now know who they're up against thanks to BT Security cc/bcc snafu

[13]Brit watchdog fines child sex abuse inquiry £200k over mass email blunder

As well as ensuring everyone understands the difference between "CC" and "BCC," the ICO recommends rules in email systems to warn when "CC" is being used, and to add some delay in sending emails to give staff time to correct errors before a message is sent. The watchdog also advised that people should turn off those annoying seemingly helpful autocomplete functions that might result in an unexpected email address being used.

The ICO also issued a reminder that email might not be the best transfer method, even if using "BCC." It noted that even if a third-party provider is being used to send emails on behalf of an organization, the organization's own requirements must be followed.

"Email," said the ICO, "has increasingly become the default choice for efficiently sharing information, but this doesn’t always make it the best choice." ®

Get our [14]Tech Resources



[1] https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/email-and-security/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXwx0rKKzWZPVXzUFf91OAAAAEI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2023/12/13/mod_bcc_email_fine/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXwx0rKKzWZPVXzUFf91OAAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXwx0rKKzWZPVXzUFf91OAAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/03/31/nhs_highland_reprimanded_by_data/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXwx0rKKzWZPVXzUFf91OAAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2021/10/20/bcc_fail_nhs_digital/

[9] https://www.theregister.com/2021/09/21/mod_email_fail_afghan_interpreters_data/

[10] https://www.theregister.com/2020/07/29/substack_privacy_fail/

[11] https://www.theregister.com/2020/03/25/watford_community_housing_data_breach/

[12] https://www.theregister.com/2019/11/12/bt_security_cc_bcc_email_fail/

[13] https://www.theregister.com/2018/07/18/ico_hands_sexual_abuse_inquiry_200k_fine_for_security_breach/

[14] https://whitepapers.theregister.com/



where a sender has misused the 'BCC' field

heyrick

I'm not sure I'd say that it was misused , that seems to be unfairly stigmatising the BCC. It's more like they simply didn't use it, leading to the obvious information exposure.

I have the same thing at work. Email notification about stuff. Sent from somebody to somebody else, with dozens of names in the CC field (including some personal addresses for people like me who don't have a work account).

I did try to "educate" them, so the response was to mail me separately... when they remembered . So I gave up, and am happy that I gave them a specific email address.

This sort of thing should be mandatory training for everybody that deals with email, especially in these GDPR days...

Pascal Monett

Came here to say the same thing.

You cannot misuse the BCC field. It is purpose-built to protect email addresses.

What you are doing is misusing CC, or SendTo.

But, obviously, administrative busybodies are not email-savvy enough to understand the difference.

jake

"You cannot misuse the BCC field."

Of course you can, by BCCing the competition when reporting to The Board that MegaProject has just slipped another calendar quarter, for example.

I'll leave it as an exercise for the reader to figure out why using the BCC instead of sending it under separate cover might work better for your NefariousPlan[tm].

Oh FFS !

JimmyPage

How fucking difficult is it for programmers to wrap a tiny sanity check around the "To/CC/BCC" fields in their shitty email "apps" to pause for a second if there are more than (say) 10 people in the field ?

"Your email appears to be going to more than 10 people, and may include more people on the BCC list. Do you wish to check before sending ?"

for example. With an additional flag to enforce it for more paranoid organisations.

Or or we waiting for Apple to fucking patent it ?

Accidentally Shot

Colonel Gray, of Petaluma, came near losing his life a few days ago,
in a singular manner. A gentleman with whom he was hunting attempted to
bring down a dove, but instead of doing so put the load of shot through the
Colonel's hat. One shot took effect in his forehead.
-- Sacramento Daily Union, April 20, 1861