Electoral Commission Criticized for Cybersecurity Lapses Following Major Data Breach

The Electoral Commission has faced severe criticism for its failure to secure its digital systems, following a breach that compromised the data of approximately 40 million voters.

The breach occurred in August 2021 when cybercriminals infiltrated the Commission’s servers, exploiting a vulnerability in its software that had been flagged and should have been patched months prior. The hackers gained access to sensitive voter information, such as names and addresses, which remained exposed for over a year before being detected and addressed.

Earlier this year, the government attributed the breach to Chinese “state-affiliated actors,” though this accusation has been strongly denied by a Chinese embassy spokesperson, who deemed it baseless. An inquiry by the Information Commissioner’s Office (ICO) has now officially criticized the Electoral Commission for failing to safeguard its systems against such attacks.

The ICO’s findings revealed that the Commission lacked adequate security measures to protect the personal data it manages. Specifically, the report highlighted that essential security updates had not been applied to the servers in a timely manner. Additionally, the Commission’s password policies were inadequate, with many employees still using default passwords.

Stephen Bonner, Deputy Commissioner at the ICO, remarked, “The Electoral Commission is responsible for safeguarding the personal information of millions of individuals who trust that their data is secure. Basic security practices, like regular updates and strong password management, could have prevented this breach.”

Bonner noted that while the data exposure was significant, there was no evidence suggesting misuse of the personal information or direct harm caused by the breach. The Commission has since implemented significant changes to enhance its cyber defenses, with improvements endorsed by cybersecurity experts, including the ICO. They have pledged ongoing investment in bolstering their security infrastructure.

In response, an Electoral Commission spokesperson expressed regret over the inadequate protections that failed to prevent the cyberattack. They assured that comprehensive changes to their security practices have been made and that they are committed to continuous enhancement of their systems.

More Articles & Posts