Nadine Dorries, a British MP, has made news over the past few weeks after admitting on Twitter that she shares the password to her work PC with other staff in her office and even “interns on exchange programs”. According to Dorries, the main reason for this is that her staff can access a shared mailbox on the PC and reply to constituents. More worrying still, in wake of the backlash directed at Dorries, other MPs have come forward and admitted to the practice, revealing a worrying trend. In a further statement that showed up Dorries’ lack of data protection savvy, she tweeted that since she was backbench MP without access to government documents, there was nothing sensitive to access. Dorries (and hopefully all other MPs sharing their passwords) are in for a rude awakening, however, as not only is sharing passwords against the rules of parliament in the UK, but even information as basic as an address book constitutes Personally Identifiable Information (PII) which is subject to strong protection under existing data protection laws – and will be protected even more fiercely under the upcoming GDPR, even in the UK.
The Central Statistics Office has admitted to a data breach involving an error by a staff member, leading to a sever breach of data protection rules. Reports were made last week that a past employee for the CSO has been sent P45s of other past and present employees in error. The past employee was outraged at the time, as she believed that 1000 people’s records had been breached.
The CSO has since issued a “sincere apology” for the incident, and volunteered that the incident had not affected 1000 people, but had actually concerned 3000 former employees.
The Central Statistics Office has apologised for a staff error which sent 3000 P45s to a past employee – a catastrophic data breach
Uber is back in the hot water again after it has revealed that over 57 million records were exposed in a 2016 data breach, which it subsequently covered up. This news comes not long after Uber ousted founder and CEO Travis Kalanick, who was suceeded in August by Dara Khosrowshahi. Kalanick was forced out of his own company due to a litany of scandals, and now Khosrowshahi is keen to do things the right way – hence the fresh statement declaring the breach. However, this has put Uber into a very troubling situation as not only do they face legal action for covering up a data breach, but it has also revealed an incredibly poor security culture within the company.
Uber will already be subject to regular external data audits for the next 20 years due to a previous, much smaller data breach
Credential Stuffing is a common practice in cyber crime where a hacker or cyber criminal gains access to a user’s email addresses and password, and proceeds to try that password against other accounts/services belonging to that individual. This is performed based on the knowledge that users often reuse the same passwords between different accounts/services, albeit sometimes with slight variations.
This is a highly effective means of attack, as users may change passwords for services that they are aware have been breached, but may not think to change that password where it is in use on other accounts. Credential stuffing is also commonly used when attempting to commit identity theft against a user.
It is highly recommended that all users do not reuse passwords between services, and to use a password manager if required to help them remember distinct, secure passwords.
Traditionally, cyber security has been seen as an IT department’s problem. They make sure everyone has antivirus on their PCs and take care of the firewall – and as long as they’re doing it right, then everyone else is safe… right? This has lulled users and business owners into a false sense of security of late, believing that cyber security simply isn’t their area or that it’s not in their job description. However, this attitude is now being taken advantage of in a big way by cyber criminals, who have discovered that individual users are much easier to target and deceive. As a result, users often takes actions which inadvertently allows the hackers to bypass the IT security systems. Traditional antivirus is dead, and even more advanced next-generation antivirus simply can’t stop the most deadly attacks. Now, everyone in an organisation has a part to play in keeping it secure, from the bottom all the way up to the CEO.