The UK Electoral Commission disclosed that it had been the victim of a complex cyber attack. Hostile actors had access to its systems from August 2021 until they were detected in October 2022, including copies of the electoral registers.
What happened
- The registers held names and addresses of people in Great Britain registered to vote between 2014 and 2022, and of overseas electors.
- The Commission estimated that around 40 million people’s data may have been accessible.
- It was criticised for waiting around ten months after detection before telling the public.
- In March 2024 the UK government said a China state-affiliated actor was responsible for the compromise.
Why it mattered
The incident raised concerns about the security of democratic institutions and about how the data could be combined with other sources for profiling or targeting. The ICO later issued the Commission with a reprimand, citing failures including unpatched servers and weak password practices.
Lessons for organisations
Organisations should keep systems patched, monitor for long-term intruders, and plan how and when to notify affected people. Cyber Essentials offers a baseline for these controls. Timely disclosure also helps affected people protect themselves.
Source: TechCrunch
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.