607,000 records pulled from two systems: Turing Scheme & Help Desk portals.
Names, e-mail addresses, phone numbers, job titles of education sector contacts incl. govt officials.
And just *how* is a national digital ID system viable with such serious breaches?
Not a good week for Data Breach Britain.
- Dept. for Education: 607,000 records pulled from two portals incl. details of govt officials.
- UKGI: 51 govt officials details left exposed for 40hrs.
Cybersecurity resilience must be the #1 priority, not One Login centralisation.
- Britons don't like centralised state identity systems
- Britons don't like National ID
- The state has had at least 20 years to modernise infrastructure & strengthen cybersecurity
- The state dream of modern digital governance is not achievable
https://t.co/uxZskLELWS
The Department for Education has referred itself to the Information Commissioner’s Office after hackers gained access to hundreds of thousands of lines of information in a cyberattack.
Story ⬇️
https://t.co/dysS633WxQ
Key findings:
- Data breach not discovered for 1.5 years
- Data breach was preventable
- Extraordinary secrecy used by HMG
- Not simply human error: poor systems, weak oversight
A public interest existed & the public should have been informed a breach had occurred.
Attacks keep on coming because the crims keep getting hits & using pulled data for secondary attacks.
The painful truth is that the govt haven't learned from past mistakes yet want to modernise digital services. It's dangerous and it's going to cost the public dearly.
They're not just soft targets, they're high-value targets.
Imagine a scenario where One Login is integrated with DfE on an identity verification level using SSO.
You're looking at an even greater risk of compromise & larger blast surface potentially impacting multiple depts.
607,000 records pulled from two systems: Turing Scheme & Help Desk portals.
Names, e-mail addresses, phone numbers, job titles of education sector contacts incl. govt officials.
And just *how* is a national digital ID system viable with such serious breaches?
@DarrenPlymouth Of course it won't. Digital ID [verification] has been used combined in both the UK private & public sector for 10+ years and it hasn't prevented breaches. In fact, it could increase the threat surface for them.
DfE et al are attempting to play down about containment, but from what we've seen so far, there's a lot of other linkable PII involved in the datasets.
🚨BREAKING: The UK Department for Education was hacked by the ransomware group 'ExfilSquad' on July 26th.
Some 600,000 contact records are said to have been affected containing PII such as names, emails, phone numbers.