By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

News Junction

Notification Show More
Font ResizerAa
  • Home
  • World News
    World NewsShow More
    Fed Chair Powell won’t be fired but should cut interest rates
    Fed Chair Powell won’t be fired but should cut interest rates
    April 23, 2025
    Gunmen open fire on tourists, killing over 20 people at Kashmir resort – National
    Gunmen open fire on tourists, killing over 20 people at Kashmir resort – National
    April 23, 2025
    The government wants you to get paid not to use Google search
    The government wants you to get paid not to use Google search
    April 22, 2025
    How effective and safe are measles vaccines?
    How effective and safe are measles vaccines?
    April 22, 2025
    Vietnam clamps down on fraud on US exports, document shows
    Vietnam clamps down on fraud on US exports, document shows
    April 22, 2025
  • Business
    BusinessShow More
    Ukraine blows up bridges to consolidate its positions in Russia
    Ukraine blows up bridges to consolidate its positions in Russia
    August 18, 2024
    Commentary: AI phones from Google and Apple will erode trust in everything
    Commentary: AI phones from Google and Apple will erode trust in everything
    August 18, 2024
    The most famous Indian Dishes – Insights Success
    The most famous Indian Dishes – Insights Success
    August 18, 2024
    Life on the road as a female long rides cyclist
    Life on the road as a female long rides cyclist
    August 18, 2024
    UK inflation rises to 2.2%
    UK inflation rises to 2.2%
    August 18, 2024
  • Cryptocurrency
    CryptocurrencyShow More
    Solana Hits 2, Cardano Stalls, But Cold Wallet’s Presale Could be the Real Winner of 2025
    Solana Hits $132, Cardano Stalls, But Cold Wallet’s Presale Could be the Real Winner of 2025
    April 23, 2025
    Dogecoin Price Struggles With alt=
    Dogecoin Price Struggles With $0.15: Machine Learning Algorithm Reveals What Is In Store For Rest Of April
    April 23, 2025
    COIN, MSTR Rally as Bitcoin Miners BTDR, MARA, RIOT Surge Over 10%
    COIN, MSTR Rally as Bitcoin Miners BTDR, MARA, RIOT Surge Over 10%
    April 23, 2025
    BTC, ETH, XRP, BNB, SOL, DOGE, ADA, LEO, LINK, AVAX
    BTC, ETH, XRP, BNB, SOL, DOGE, ADA, LEO, LINK, AVAX
    April 22, 2025
    Bitcoin traders warn BTC price rally may stall at K
    Bitcoin traders warn BTC price rally may stall at $90K
    April 22, 2025
  • Technology
    TechnologyShow More
    How to Improve Your Spotify Recommendations
    How to Improve Your Spotify Recommendations
    August 18, 2024
    X says it’s closing operations in Brazil
    X says it’s closing operations in Brazil
    August 18, 2024
    Supermoon set to rise: Top tips for amateur photographers | Science & Tech News
    Supermoon set to rise: Top tips for amateur photographers | Science & Tech News
    August 18, 2024
    Scientists Want to See Videos of Your Cat for a New Study
    Scientists Want to See Videos of Your Cat for a New Study
    August 18, 2024
    OpenAI’s new voice mode let me talk with my phone, not to it
    OpenAI’s new voice mode let me talk with my phone, not to it
    August 18, 2024
  • Entertainment
  • Sports News
  • People
  • Trend
Reading: Basic failures led to hack of Electoral Commission data on 40 million people
Share
Font ResizerAa

News Junction

  • World News
  • Business
  • Technology
  • Cryptocurrency
  • Trend
  • Entertainment
Search
  • Recent Headlines in Entertainment, World News, and Cryptocurrency – NewsJunction
  • World News
  • Business
  • Cryptocurrency
  • Technology
  • Entertainment
  • Sports News
  • People
  • Trend
Have an existing account? Sign In
Follow US
News Junction > Blog > Technology > Basic failures led to hack of Electoral Commission data on 40 million people
Basic failures led to hack of Electoral Commission data on 40 million people
Technology

Basic failures led to hack of Electoral Commission data on 40 million people

Published July 31, 2024
Share
8 Min Read
SHARE

Contents
Known vulnerabilitiesPatching failuresGuessable passwordsChina riskRemedial steps

The Information Commissioner’s Office (ICO) has issued a reprimand to the Electoral Commission after basic security errors allowed hackers linked to the Chinese state to gain access to servers containing the personal information of 40 million people.

Hackers were able to access the Electoral Commission’s Microsoft Exchange Server after the organisation failed to patch known security vulnerabilities.

The Electoral Commission disclosed in August 2023 that it had been subject to a major cyber attack in 2021, which remained undetected for 12 months.

The attackers gained access to personal information stored on the electoral register, including the names and home addresses of everyone who had registered to vote between 2014 and 2022. They also had access to the personal data of people who had opted not to register their details on the open version of the electoral register and the names of registered overseas voters.

The then Conservative deputy prime minister, Oliver Dowden, told the Commons in March 2024 that Chinese state-linked hacking groups were “highly likely” to have been behind the attack.

A separate campaign by a Chinese state-sponsored hacking group targeted the email accounts of over 40 UK parliamentarians who had spoken out against China.

Known vulnerabilities

Investigations into the attack against the Electoral Commission revealed that at least two hacking groups had accessed an on-premise Microsoft Exchange Server used to manage email and related services.

The groups exploited known vulnerabilities in the Exchange Server, which remained unpatched for three to five months after Microsoft had released fixes to the problem. The ICO found that the Electoral Commission did not have an “appropriate patching regime” in place, hence the security vulnerabilities remained.

If the Electoral Commission had taken basic steps to protect its systems, it is highly likely that this data breach would not have happened
Stephen Bonner, ICO

The Electoral Commission was also criticised for its failure to have adequate password policies in place at the time of the attack. Investigations revealed that many users were using passwords that were similar or identical to those originally allocated by the service desk.

The information commissioner, Stephen Bonner, said: “If the Electoral Commission had taken basic steps to protect its systems, such as effective security patching and password management, it is highly likely that this data breach would not have happened. By not installing the latest security updates promptly, its systems were left exposed and vulnerable to hackers.”

Patching failures

According to the ICO report, hackers were able to access the unpatched Microsoft Exchange Server in August 2021 by exploiting a vulnerability known as the ProxyShell vulnerability chain.

The vulnerability, previously identified as a critical issue by Microsoft, was regarded as an easy vulnerability for hackers to exploit and was well known in the hacking community, having been discussed by researchers at the Black Hat hacking conference in 2021.

A report commissioned by the Electoral Commission later identified a further eight vulnerabilities on the organisation’s Microsoft Exchange Servers that could have been exploited by hackers.

“This failing is a basic measure that we would expect to see implemented in any organisation processing personal data,” the ICO said in a formal reprimand.

Guessable passwords

The ICO found that the Electoral Commission did not have a dedicated password management policy in place and that the only password guidance was “do not reveal or write down passwords”.

Security investigators discovered that passwords set up by the Electoral Commission’s IT service desk when it created new accounts or reset old accounts were insecure. The investigators were able to rapidly crack 178 active accounts using passwords that were identical or similar to passwords provided by the service desk. An audit found that the service desk’s practice of reusing passwords made the Electoral Commission’s accounts “highly susceptible” to cracking.

The Electoral Commission reported an incursion to the National Cyber Security Centre (NCSC) after an employee discovered that spam emails were being sent from the Electoral Commission’s Exchange Server in October 2021.

At the time, the Electoral Commission said it considered the issue to be an isolated incident, according to the ICO’s reprimand.

The Electoral Commission was aware of problems with outdated infrastructure and reported that as it was planning to move its infrastructure towards the cloud, “remedial action with the old servers was limited”, the ICO’s report stated.

China risk

In May 2024, GCHQ director Anne Keast-Butler warned that China’s cyber capabilities posed a significant threat to the UK and other countries.

“China has built an advanced set of cyber capabilities and is taking advantage of a growing commercial ecosystem of hacking outfits and data brokers at its disposal,” she said.

These include a campaign by a Chinese state-sponsored hacking group, known as APT31, that targeted the email accounts of more than 40 UK parliamentarians who had spoken out against China.

The Foreign, Commonwealth and Development Office summoned the Chinese ambassador to the UK to answer questions about the hacks in March 2024.

Remedial steps

The Electoral Commission said it had taken a series of remedial steps following the incident, including implementing a technology modernisation plan and introducing a managed infrastructure support service.

The Electoral Commission has also implemented services to monitor servers, firewalls and internet traffic, and to support threat and vulnerability programmes.

In addition, it has introduced password policy controls in Microsoft’s Active Directory and implemented multifactor authentication (MFA) for all users.

Information commissioner Bonner said that although an unacceptably high number of people were affected by the hack, the ICO had no reason to believe any personal data had been misused and there was no evidence that “direct harm” had been caused by the breach.

A spokesman for the Electoral Commission said: “We regret that sufficient protections were not in place to prevent the cyber attack on the commission. Since the cyber attack, security and data protection experts – including the ICO, National Cyber Security Centre and third-party specialists – have carefully examined the security measures we have put in place and these measures command their confidence.”

#Basic #failures #led #hack #Electoral #Commission #data #million #people

TAGGED:basicCommissionDataelectoralfailuresHackledMillionpeople
Share This Article
Facebook Twitter Pinterest Whatsapp Whatsapp LinkedIn Email Copy Link Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Starbucks (SBUX) Q3 2024 earnings Starbucks (SBUX) Q3 2024 earnings
Next Article Bull Market Alert: Russia Joins Crypto, America Planning Bitcoin Reserves – Top Coins to Buy Now Bull Market Alert: Russia Joins Crypto, America Planning Bitcoin Reserves – Top Coins to Buy Now

You Might Also Like

Nintendo, Monsters of the Dark Universe, and More Collide at Universal’s Epic Theme Park
Technology

Nintendo, Monsters of the Dark Universe, and More Collide at Universal’s Epic Theme Park

January 31, 2024
Interview: Abhijit Dubey, global CEO, NTT Data
Technology

Interview: Abhijit Dubey, global CEO, NTT Data

July 27, 2024
Blue Beetle’s Post-Credits Scenes, Explained
Technology

Blue Beetle’s Post-Credits Scenes, Explained

August 19, 2023
Elon Musk is now a villain in Joe Biden’s presidential campaign
Technology

Elon Musk is now a villain in Joe Biden’s presidential campaign

July 19, 2024

About Us

NEWS JUNCTION (NewsJunction.xyz) Your trusted destination for global news. Stay informed with our timely and accurate reporting on diverse topics, including politics, technology, science, entertainment, sports, and more. Count on us for unbiased and reliable updates at your fingertips.

Quick Link

  • About
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • Contact

Top Categories

  • World News
  • Business
  • Technology
  • Entertainment
  • Cryptocurrency
  • Sports News
  • Trend
  • People

Subscribe

Subscribe to our newsletter to get our newest articles instantly!

    © 2023 News Junction.
    • Blog
    • Advertise
    • Contact
    Welcome Back!

    Sign in to your account

    Username or Email Address
    Password

    Lost your password?