The UK Electoral Commission disclosed a data breach that exposed the personal information of voters in the United Kingdom between 2014 and 2022. The Commission notified the Information Commissioner’s Office.
According to the data breach notification, the incident began two years ago, likely in August 2021, and was identified in October 2022 after suspicious activity was detected on the systems.
The threat actors had access to the Commission’s servers which held its emails, its control systems, and copies of the electoral registers.
They also had access to reference copies of the electoral registers, which are held by the Commission for research purposes and to enable permissibility checks on political donations.
The exposed voters’ personal data contained in email system includes name, first name and surname, email addresses (personal and/or business), home address if included in a webform or email, contact telephone number (personal and/or business), the content of the webform and email that may contain personal data, and any personal images sent to the Commission.
The Commission pointed out that Electoral Register data not held anonymous registrations and addresses of overseas electors registered outside of the UK.
The UK Electoral Commission stated that the cyberattack had no impact on any elections or an individual’s voter registration.
However, the Commission admitted that threat actors could combine the accessed information with other data in the public domain. Then threat actors can use aggregated data for a broad range of fraudulent activities, including identity theft and phishing attacks.
All the impacted individuals are suggested to remain vigilant for suspicious emails.
Image Credit : Financial Times















Comments