Attacks/Breaches

4/12/2019
10:40 AM
50%
50%

Home Office Apologizes for EU Citizen Data Exposure

The Home Office has admitted to compromising private email addresses belonging to EU citizens hoping to settle in the UK.

The UK's Home Office has issued an apology to hundreds of EU citizens after accidentally sharing their private email addresses.

All victims were applying for "settled status" in the UK as part of a new program launched last June. EU citizens who have been in the UK for a minimum of five years are able to receive settled status, a designation that would let them live and work there after Brexit. The Home Office reports more than 400,000 EU nationals have applied; this incident affects 240 of them.

On April 7, the Home Office sent an email to some applications requesting they resend information – but it didn't check "BCC," exposing contact info for applicants in the email.

Upon recognizing the mistake, the Home Office sent an email apologizing to affected applicants and requesting they delete the original email. It also said it had improved systems to prevent a similar mistake from happening in the future. Still, some critics say the process to obtain settled status has proved tedious; others express distrust in the Home Office's ability to handle data.

"We've already heard far too many cases of EU citizens facing technical problems or being wrongly refused," said Ed Davey, home affairs spokesman for the Liberal Democrats, to the Financial Times. "Now 240 have had their privacy compromised."

This is the second time Home Office has apologized for data misuse in recent days. Earlier this week, it confirmed people and organizations listed as having interest in the Windrush scandal compensation scheme were sent emails with email addresses of other interested parties.

Read more details here.

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/15/2019 | 10:29:23 AM
BCC Blunder
Facepalm. If the individuals on that list want to salvage their personal emails they should use whitelisting. Otherwise they may be better off creating a new one before getting spammed to death.
Russia Hacked Clinton's Computers Five Hours After Trump's Call
Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
Tips for the Aftermath of a Cyberattack
Kelly Sheridan, Staff Editor, Dark Reading,  4/17/2019
Why We Need a 'Cleaner Internet'
Darren Anstee, Chief Technology Officer at Arbor Networks,  4/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-7303
PUBLISHED: 2019-04-23
A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to match 64-bit ioctl(2) commands on a 64-bit platform; however, the Linux kernel only uses the lower 32 b...
CVE-2019-7304
PUBLISHED: 2019-04-23
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
CVE-2019-0223
PUBLISHED: 2019-04-23
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1...
CVE-2017-12619
PUBLISHED: 2019-04-23
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
CVE-2018-1317
PUBLISHED: 2019-04-23
In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.