, , , , ,

Electoral Commission hack exposed data of 40 million UK voters

The personal information of approximately 40 million U.K. voters was exposed to hackers for more than a year after the Electoral Commission fell victim to a “complex cyberattack.”

The Electoral Commission, the watchdog responsible for overseeing elections in the U.K., said in a statement on Wednesday that it first identified suspicious activity on its network in October 2022, but later confirmed that unnamed “hostile actors” had first accessed its systems over a year earlier in August 2021.

When asked by TechCrunch why the organization has only just notified those impacted, Electoral Commission spokesperson Andreaa Ghita said there were “several steps” that the Commission needed to take before it could make the incident public.

“We needed to remove the actors and their access to our system. We had to assess the extent of the incident to understand who might be impacted and liaise with the National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO). We also needed to put additional security measures in place to prevent any similar attacks from taking place in the future,” the spokesperson said.

These measures include strengthening its network login requirements, improving its threat monitoring capabilities and updating its firewall policies, according to an FAQ published by the Electoral Commission.

The Electoral Commission’s spokesperson told TechCrunch that the incident, which saw hackers access the Commission’s email, control systems, and copies of the electoral registers, may have affected as many as 40 million U.K. voters. This includes anyone who registered to vote between 2014 and 2022, as well as the names of those registered as overseas voters.

‘No impact’ to U.K. election security

While the Electoral Commission has been unable to ascertain whether the attackers exfiltrated data held on its systems, it says that data potentially impacted includes U.K. citizens’ full names, email addresses, home addresses, phone numbers, any personal images sent to the Commission, and any details provided via email or online contact forms.

The watchdog notes that while much of this information is already in the public domain, it could be combined with other data to infer patterns of behavior or to identify and profile individuals.

The Electoral Commission added that there has been “no impact” on the security of U.K. elections.

“The UK’s democratic process is significantly dispersed and key aspects of it remain based on paper documentation and counting,” the Commission states. “This means it would be very hard to use a cyberattack to influence the process.”

It’s not yet known who was behind the attack. The Electoral Commission said “we do not know who is responsible for the attack,” and the NCSC declined to answer when asked by TechCrunch.

“We provided the Electoral Commission with expert advice and support to aid their recovery after a cyber incident was first identified,” the NCSC spokesperson said, who declined to provide their name. “Defending the UK’s democratic processes is a priority for the NCSC and we provide a range of guidance to help strengthen the cyber resilience of our electoral systems.”


Do you work at the Electoral Commission? Do you have more information about the cyberattack? You can contact Carly Page securely on Signal at +441536 853968, or by email. You can also contact TechCrunch via SecureDrop.

https://techcrunch.com/2023/08/08/electoral-commission-hack-40-million-uk-voters/


May 2024
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  

About Us

Welcome to encircle News! We are a cutting-edge technology news company that is dedicated to bringing you the latest and greatest in everything tech. From automobiles to drones, software to hardware, we’ve got you covered.

At encircle News, we believe that technology is more than just a tool, it’s a way of life. And we’re here to help you stay on top of all the latest trends and developments in this ever-evolving field. We know that technology is constantly changing, and that can be overwhelming, but we’re here to make it easy for you to keep up.

We’re a team of tech enthusiasts who are passionate about everything tech and love to share our knowledge with others. We believe that technology should be accessible to everyone, and we’re here to make sure it is. Our mission is to provide you with fun, engaging, and informative content that helps you to understand and embrace the latest technologies.

From the newest cars on the road to the latest drones taking to the skies, we’ve got you covered. We also dive deep into the world of software and hardware, bringing you the latest updates on everything from operating systems to processors.

So whether you’re a tech enthusiast, a business professional, or just someone who wants to stay up-to-date on the latest advancements in technology, encircle News is the place for you. Join us on this exciting journey and be a part of shaping the future.

Podcasts

TWiT 979: Musk-stache – Solar Storms, Apple and OpenAI, Tesla Layoffs This Week in Tech (Audio)

Solar Storm Knocks Out Farmers' Tractor GPS Systems During Peak Planting Season Apple Closes in on Deal With OpenAI to Put ChatGPT on iPhone Apple Will Revamp Siri to Catch Up to Its Chatbot Competitors Google is getting even worse for independent sites Musk Plans More Layoffs as Two Senior Tesla Executives Depart At Tesla, a Wild Week That Defined the Company's Future TikTok Sues US Government Over Potential Ban Telegram vs. Signal Sony reverses unpopular Helldivers 2 decision after blistering player reaction Apple apologizes for 'Crush' iPad Pro ad that sparked controversy Host: Leo Laporte Guests: Paris Martineau, Sam Abuelsamid, and Mike Elgan Download or subscribe to this show at https://twit.tv/shows/this-week-in-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: bitwarden.com/twit NetSuite.com/TWIT mintmobile.com/twit eufy.com ZipRecruiter.com/Twit
  1. TWiT 979: Musk-stache – Solar Storms, Apple and OpenAI, Tesla Layoffs
  2. TWiT 978: Baptized in Gatorade – AI Priest, FCC Fines, Jack Dorsey Leaves Bluesky
  3. TWiT 977: Gahoo Yoogle – TikTok Ban, Intel's Struggles, Google's Ensh*ttification
  4. TWiT 976: Serial Churners – Netflix Earnings, Cybertruck Recall, FISA
  5. TWiT 975: You Don't Want to Make Gandhi Mad – AI Music, Broadband Nutrition Labels