Insider steals 79,000 email addresses at work to promote own business
- Reference: 1708426892
- News link: https://www.theregister.co.uk/2024/02/20/insider_steals_79000_email_addresses/
- Source link:
The UK's Stratford-on-Avon District Council concluded its investigation into a November data breach last week, finding tens of thousands of email addresses stolen from a garden and waste collection database.
A database holding information on Warwick District Council residents was also raided and has been accessible due to a joint working arrangement between the two councils.
[1]
The total number of email addresses stolen stands at around 79,000, Stratford-on-Avon District Council confirmed.
[2]
[3]
These email addresses were stolen, it's said, for the purposes of promoting the individual's business – which was unrelated to the council. Unsurprisingly, the person responsible is no longer employed there.
"On behalf of the council I would like to apologize for this data breach," [4]said David Buckland, chief executive at Stratford-on-Avon District Council. "When the Council was alerted to this, we immediately began a full investigation to understand how this happened.
[5]
"It is important to stress that this information only contained email addresses, it did not contain any bank details, or names and addresses. We have concluded through our investigations that this data breach was a deliberate act by an individual, and not a breakdown of the robust internal controls we have in place."
The individual behind the data theft, who has not been named, was referred to Warwickshire Police and was subject to investigation from law enforcement, but has escaped with an official caution – a slap on the wrist.
Apparently they "apologized sincerely" and the police confirmed that all data had been deleted.
[6]Romanian hospital ransomware crisis attributed to third-party breach
[7]Infosys subsidiary named as source of Bank of America data leak
[8]Medway Council reforms eforms to stop blurting out residents' details
[9]City of London ditches Oracle for SAP in search of ERP enlightenment
The [10]Information Commissioner's Office (ICO) was also notified and decided not to take the matter further.
"Despite the robust procedures in place to protect resident's information, it has been very disappointing to find that an employee has acted independently for their own gain," said Chris Elliott, chief executive at Warwick District Council.
[11]
"I would like to reassure our residents that this was an isolated incident, and I am satisfied that the necessary steps have been taken and the data breach is now resolved." ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZdTawIwHBaL4a122C7PjEAAAAMM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZdTawIwHBaL4a122C7PjEAAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZdTawIwHBaL4a122C7PjEAAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.stratford.gov.uk/news/press.cfm/current/1/item/138166
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZdTawIwHBaL4a122C7PjEAAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2024/02/14/romanian_hospital_ransomware_crisis/
[7] https://www.theregister.com/2024/02/13/infosys_bank_of_america_leak/
[8] https://www.theregister.com/2019/07/08/medway_data_breach/
[9] https://www.theregister.com/2024/02/19/city_of_london_sap_si/
[10] https://www.theregister.com/2024/01/22/ico_fines_spam_slinging_financial/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZdTawIwHBaL4a122C7PjEAAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Re: Safety
"cod knows how long"?
Sounds a bit fishy to me!
(sorry - your typo made me laugh).
You what?
> We have concluded through our investigations that this data breach was a deliberate act by an individual, and not a breakdown of the robust internal controls we have in place.
Which utter moron wrote this. What are internal controls for, if not for this kind of thing. Deliberate act by an internal is threat number one, so they either broke down, or they are not robust.
Re: You what?
But it *sounds* nice to the public...
Re: You what?
Indeed. It is totally a breakdown of internal controls.
Either that, or they weren't controlling who could download the database.
These guys are amateurs and need to go on a course.
Where is the standard response as taught in "how to manage a data breach - 101". "Lessons will be learned"
I would expect staff can only access one record at a time - there should be no need to access all the data at once.
Re: These guys are amateurs and need to go on a course.
>>I would expect staff can only access one record at a time - there should be no need to access all the data at once.
Any DBA of a database can access all the data using a suitable command shell/query language.
Obviously that shouldn't be available to normal staff but we don't know if the miscreant in this case was a DBA or Normal staff... nor do we know if normal staff had access through command line tools by intent or omission.
Re: These guys are amateurs and need to go on a course.
Even if the person wasn't a DBA, they might be able to use an office tool like Excel, or other reporting tools. Some reporting tools provide the ability to download the data as csv, for easy onward use.
Slap on the wrist?
Which is exactly why this behaviour will continue, it's not considered any more serious than nicking pencils from the stationery cupboard. At the very least, this moron should be required to personally compensate everyone whose email he compromised.
Re: Slap on the wrist?
this moron \wcrook should be required to personally compensate everyone whose email he compromised.
A minimum of £5/head would be good. This might deter other, in the future, of doing likewise.
Every Saturday in the local market in the stocks would be a nice addition - especially of the rotten tomatoes were to be paid for by him.
A slap on the wrist?
"The individual behind the data theft, who has not been named, was referred to Warwickshire Police and was subject to investigation from law enforcement, but has escaped with an official caution – a slap on the wrist. "
That all???
No deterrent to stop it happening again by a "rogue".
"Apparently they "apologized sincerely" and the police confirmed that all data had been deleted."
Do it and then beg forgiveness?????? How sincerely?
How is anyone certain that ALL COPIES have been deleted?
Re: A slap on the wrist?
There's also the seeking alternate employment part. Assuming the side hustle isn't up an running enough to pay the bills.
Re: A slap on the wrist?
No need to make a copy, just recover from the waste-basket once the cops have left.
Apparently they "apologized sincerely" and the police confirmed that all data had been deleted.
To whom? Not, I'll be bound, to the 79,000 whose email addresses were nicked and, presumably, spammed.
So the only penalty was that they lost their job but as they had started a new business it may well have been that they had quit anyway. The best that can be hoped for is that, having proved themselves untrustworthy to do business with and probably pissed off 79,000 potential customer with spam the business fails.
Safeguards
I had a contract at a place. They were using a Popular Cloud-Based CRM. They made use of the security feature where only their egress IP was able to access their stuff. Which was fine - until the ex-employee was able to connect to the guest WiFi from outside the building and slurp all the contacts. Marketing had dealt with the CRM people without involving IT so no leavers' process to delete the account.
Re: Safeguards
Well they can safely say that it is not a breakdown of internal procedures, since no internal procedures were actually used.
Re: Safeguards
Well I wouldn’t say IT was entirely blameless, the guest WiFi could obviously connect to internal resources, and must have used static credentials otherwise how would they have gained access.
Neither of these seems to be good practice.
I use individual emails for every company I deal with.
So if I'm signing up for one service, I know exactly what email I gave them, and if I get spam, I know exactly where that address came from. And if I don't "create" an address for a company, there's no way to contact me except on a generic account (e.g. my name) which I never give out.
Then I got an email selling furniture for schools (which was quite clearly a new company spamming to drum up business). I wondered how they had got hold of my address as it wasn't anything I'd ever signed up for. Turned out that the email address they were using was the one I had given RM (remember them?). And they seemed to be an entirely unrelated company.
I unsubscribed, and they still spammed me relentlessly, so I called them up. It took a while for them to get what I meant, and then got to someone who I could actually confront, who was instantly red-faced and sheepish.
Turned out that their director was a former employee of RM, who had recently left to set up a company of their own, and in the process had stolen the entire RM address book and used it to spam all their customers.
To say they were shocked I'd managed to expose this in the matter of hours of being sent an email, that they then panicked trying to undo it all, and that they promised rather comprehensively I would never get another email from them ever again (that was my deal that I offered... I don't care where you got the address from, but if I receive a single further email from you, there'll be a nice message winging its way to RM's data protection department) is an understatement. They soiled themselves.
I never did get another email, nor buy anything from them. And I kind of judge RM that their customer address database / CRM / whatever lets you just exfiltrate the entire contents like that.
But it happens all the time, and it just shouldn't be possible. Why does anyone working at RM (or indeed anywhere) need to see my email address, or be able to export the entire address book to a third party device?
I think in your place I might have contact RM first. They're clearly the one's ultimately responsible for letting an employee walk off with the data. Assuming it was post GDPR they should also have reported themselves to the ICO.
Then I'd have told the new company that they had to report themselves to the ICO within the statutory72 hours.
And made clear that I'd report them both myself before the 72 hours were up so if they wanted to get in first to look good they'd better move.
""It is important to stress that this information only contained email addresses, it did not contain any bank details, or names and addresses."
Well, it probably did contain some names / name related information.
Many people have email addresses that include their surname and forename (albeit may often be abbreviated forename e.g. Rich instead of Ricard etc.) or surname (plenty of friends I know where a couple share email address for "general" emails so I would email them at something like thesmiths@whatever.com)
So, I'm betting at least some emails could be directly matched to people (given addresses only covered a small area of the UK), or if not precisely matched, could be just one of a handful of people in taht part of the West Midlands.
Any DBA of a database can access all the data using a suitable command shell/query language.
Not true.
[1]Homomorphic encryption
The fact it's not more widely used suggests the powers that be aren't so keen on teh idea of data they can't slurp.
[1] https://en.wikipedia.org/wiki/Homomorphic_encryption
Re: Any DBA of a database can access all the data using a suitable command shell/query language.
Take off the tin foil hat
Other reasons include it being difficult and sometimes it is necessary to read data for support purposes.
Looking at that Wikipedia article it seems at first glance that what is possible is limited, and it's not at all straightforward. It also raises the suspicion that customising software with new functionality with reasonably short timescales is likely to be difficult. Time is money, companies are going to take the quickest reasonably secure option.
I know of an instance where a developer decided to be 'clever' and use some encryption technologies so no-one, including support staff or development, could read certain stored documents. Unfortunately in their usual rush to use a fancy new technology and gain plaudits/money they didn't understand encryption ciphers well enough and it resulted in unwanted information disclosure.
It wouldn't have happened if they hadn't tried to use a sophisticated approach, or if they'd asked someone with even a vague knowledge of what types of encryption should and should not be used.
The number of people that understand even basic encryption limitations is distressingly low. There's no excuse for it, but it remains the case. The number of people that can safely code and implement anything beyond calling a turnkey library is vanishingly small.
Safety
It's so reassuring to know that for instance our health records will be held in one place, so there is totally no chance that a rogue employee will download it and put it up on Dark Net, so that we could access them quicker without having to wait for Subject Access Request to be processed cod knows how long for.