ICO Reprimands Electoral Commission Over Cyberattack

19th August 2024

Could inadequate security measures be to blame?

The Electoral Commission is an independent body in the UK that oversees elections, ensures the integrity of party and election finances, and holds the personal data of registered voters on the electoral register, which includes around two-thirds of all UK residents. The ICO, the UK’s data protection authority issued a reprimand to the Electoral Commission following a data breach of their servers. The ICO stressed that if basic security measures had been in place, the breach would probably not have occurred.

Electoral Commission Data Breach Details

In August 2021, hackers gained access to the Electoral Commission’s Microsoft Exchange Server and accessed the personal information of 40 million people including names and addresses. They continued to access the server for over a year until October 2022 when the Electoral Commission discovered the data breach. They then failed to disclose the data breach either publicly or to the ICO, as required under GDPR Articles 33 and 34, until August 2023, over a year after its discovery. In the UK, reportable personal data breaches should be made to the ICO within 72 hours of the Controller becoming aware of the breach.

The Electoral Commission has had problems in the past, from accusations of fraudulent postal voting to running out of ballot papers in the 2010 election. After the breach was disclosed to the ICO, they investigated and discovered that the hackers were able to access the secure servers and obtain personal data due to the following:

  • The Electoral Commission did not have appropriate security measures in place
  • They did not keep email servers up to date with security patches
  • They had insufficient password policies, including using default passwords 

How The Data Breach Occurred

In 2021, a chain of vulnerabilities in Microsoft Exchange Servers was discovered by the Chinese cybersecurity company DEVCORE. This chain, ProxyShell, enabled threat actors to bypass authentication and install a web shell, or executable file, that gives them remote access to data stored on the server. Microsoft has released patches for their servers to protect against ProxyShell attacks, but the Electoral Commission failed to install them. In addition to this, they frequently allowed users to continue using default passwords issued by their own service desk or passwords that would have been easy to guess. This combined with the way ProxyShell attacks are delivered by accessing a user’s mailbox and uploading the web shell as an attachment created the perfect environment for a cyberattack.

The UK Government blamed the ProxyShell attacks on hackers affiliated with China who would be highly likely to try and use this data for large-scale espionage and potential repression of UK residents deemed as ‘dissidents’ i.e. people from China who have publicly criticised the Chinese government or its policies. Despite this, the ICO’s Deputy Commissioner, Stephen Bonne, says: “ […] while an unacceptably high number of people were impacted, we have no reason to believe any personal data was misused and we have found no evidence that any direct harm has been caused by this breach.” – Source: ICO website

The Electoral Commission has now taken steps to improve its security including modernising its infrastructure, implementing a password policy and multi-factor authentication.

How Organisations Can Stay Safe

As a public sector organisation, the Electoral Commission is subject to the Network and Information Systems Regulations 2018, or NIS. The NIS regulations are intended to protect organisations that are classed as ‘operators of essential services’ or OES and ‘relevant digital service providers’ or RSDPs, and other organisations such as the Electoral Commissions that operate within UK critical national infrastructure. The NIS has established a common level of security for such organisations. 

Organisations of all sizes can protect themselves from cyberattacks and other potential data breaches by following guidance provided by the government-backed National Cyber Security Centre, or NCSC. All third-party organisations who work with government agencies must hold Cyber Essentials Plus accreditation.

The NIS only covers some organisations, but data protection laws such as the DPA 2018 and UK GDPR apply to all organisations. The NCSC’s Cyber Essentials certification scheme can provide valuable information on how to protect your organisation from cyberattacks, and general good practices to remain compliant with data protection laws.

If you need further assistance with your organisation’s data protection policies, contact us at Griffin House Consultancy for training, auditing and general guidance.

 

Author: Mike Martin LLM

Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details