Attacks/Breaches

4/12/2019
10:40 AM
50%
50%

Home Office Apologizes for EU Citizen Data Exposure

The Home Office has admitted to compromising private email addresses belonging to EU citizens hoping to settle in the UK.

The UK's Home Office has issued an apology to hundreds of EU citizens after accidentally sharing their private email addresses.

All victims were applying for "settled status" in the UK as part of a new program launched last June. EU citizens who have been in the UK for a minimum of five years are able to receive settled status, a designation that would let them live and work there after Brexit. The Home Office reports more than 400,000 EU nationals have applied; this incident affects 240 of them.

On April 7, the Home Office sent an email to some applications requesting they resend information – but it didn't check "BCC," exposing contact info for applicants in the email.

Upon recognizing the mistake, the Home Office sent an email apologizing to affected applicants and requesting they delete the original email. It also said it had improved systems to prevent a similar mistake from happening in the future. Still, some critics say the process to obtain settled status has proved tedious; others express distrust in the Home Office's ability to handle data.

"We've already heard far too many cases of EU citizens facing technical problems or being wrongly refused," said Ed Davey, home affairs spokesman for the Liberal Democrats, to the Financial Times. "Now 240 have had their privacy compromised."

This is the second time Home Office has apologized for data misuse in recent days. Earlier this week, it confirmed people and organizations listed as having interest in the Windrush scandal compensation scheme were sent emails with email addresses of other interested parties.

Read more details here.

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/15/2019 | 10:29:23 AM
BCC Blunder
Facepalm. If the individuals on that list want to salvage their personal emails they should use whitelisting. Otherwise they may be better off creating a new one before getting spammed to death.
Russia Hacked Clinton's Computers Five Hours After Trump's Call
Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
Tips for the Aftermath of a Cyberattack
Kelly Sheridan, Staff Editor, Dark Reading,  4/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11378
PUBLISHED: 2019-04-20
An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.
CVE-2019-11372
PUBLISHED: 2019-04-20
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
CVE-2019-11373
PUBLISHED: 2019-04-20
An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
CVE-2019-11374
PUBLISHED: 2019-04-20
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
CVE-2019-11375
PUBLISHED: 2019-04-20
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.