Featured Article

Parsing the UK electoral register cyberattack

What the Electoral Commission is saying (and not saying) about the massive hack of 40 million voters

Comment

Union flag bunting is seen outside Canford Cliffs Library Polling station, as people go to the polls in the local elections in 2023
Image Credits: Finnbarr Webster / Getty Images

A catastrophic breach of the United Kingdom electoral register affects tens of millions of residents following a cyberattack at the U.K. Electoral Commission.

With data on more than 40 million voters accessed by unnamed hackers, the cyberattack is already one of the U.K.’s largest ever hacks.

The Electoral Commission said the hackers accessed a “high volume” of personal information of people registered to vote in the U.K. between 2014 and 2022, including names and home addresses. The information is used for research and conducting checks on political donors. The Commission said there was no impact on the integrity of elections or any voter’s registration since “live” electoral registers are handled by local election authorities.

The cyberattack was disclosed Tuesday, more than nine months after the organization said it discovered “suspicious activity” on its network in October 2022. The Commission said the hackers first gained access more than a year earlier in August 2021.

Why the U.K. public is first hearing about it now is anybody’s guess. The Electoral Commission declined to answer our specific questions, citing an ongoing investigation by the U.K. data protection authority, the Information Commissioner’s Office. When reached, an ICO spokesperson would not say why the Commission took nine months to disclose the cyberattack.

The Electoral Commission’s website has limited details about the incident.

TechCrunch has annotated the Commission’s data breach notice 🖍️ with our analysis of what it says and what was left out, just as we did with the security incidents at LastPass and Samsung last year. You can tap each 🖍️ link and it’ll open the notice for you to follow along. Knowing what to look for when organizations publicly disclose their security incidents can help shed light on what happened.

What the Electoral Commission said in its data breach notice

The Commission is “unable” to ascertain if data was actually stolen

It’s not disputed that the hackers gained access to the Commission’s network, including its file sharing systems and email server 🖍️. It’s that the Commission does not know if data was taken or exfiltrated from its systems. The Commission’s notice specifically notes: “We have been unable to ascertain whether the attackers read or copied personal data.” 🖍️

The question really is, what monitoring and logging did the Commission have in place, if any, to detect or identify a data breach?

Accessed data includes voters’ names, addresses, and nonpublic voter information

According to the notice, the personal data accessed by the hackers includes names, email addresses and postal addresses, phone numbers 🖍️ and any correspondence that voters had with the Commission, including emails (more on that below). Voters registered to vote anonymously are not affected by the cyberattack, the Commission confirmed.

The compromised data does, however, include information on voters who opted out of having their information published in the public voter registers, which are available to anyone wanting to purchase.

Commission said suspicious logins flagged the hack

Buried in its notice, the Commission said it was first alerted to the attack “by a suspicious pattern of log-in requests to our systems” 🖍️ in October 2022. Once the Commission identified the suspicious pattern of logins, presumably the initial access was then traced back to August 2021. This means that the hackers were in the Commission’s systems for more than a year before they were noticed, and likely longer until they were fully expelled.

As a result of the security incident, the Commission said it “strengthened our network login requirements” 🖍️ but did not say specifically how. That could be anything from implementing two-factor authentication to simply improving their existing security protections.

“Hostile actor” likely suggests evidence of malice

The Commission described the hackers as “hostile actors,” 🖍️ citing its unnamed cybersecurity partners, presumably incident response with knowledge of investigating cyberattacks. We don’t know what the evidence is, or what the Commission constitutes as “hostile.” Given this, we can likely conclude that whatever access or activity the hacker gained suggests a level of malice not typically carried out by good-faith security researchers in the pursuit of reporting and fixing security flaws.

What we don’t know about the Electoral Commission hack

The Commission does not know who is behind the breach

We don’t know what the motivations of the hackers are, or whether they are financially driven or a state-backed hacker conducting espionage.

The Commission said nobody has “claimed responsibility” 🖍️ for the hack, suggesting that the hackers have not contacted the Commission with an extortion demand, such as a ransom to return encrypted or stolen data. The Commission also said that “we do not know who is responsible for the attack.” 🖍️

This is important as it suggests neither the hackers have claimed responsibility nor has the Commission heard from the hackers. Where there isn’t a financial motivation for a cyberattack, one might instead wonder what value this data has to an adversarial nation.

It’s not known how the Commission’s email server was compromised

A key part of this cyberattack was the hackers’ access to the Commission’s email server. According to the notice, the hackers gained access to copies of the electoral registers 🖍️ and its email servers, which the Commission said contains “a broad range of information and data,” 🖍️ without specifying more.

Commission spokesperson Andreea Ghita said that as a result anyone who contacted the Commission by email or through its web form “will have provided data that was accessible as part of this attack.”

The Commission runs largely a Windows-based environment. TechCrunch identified that the Commission’s email server is a self-hosted Exchange email server, which was online until at least August 2022, per its listing in Shodan, a database for public servers and databases. The Exchange server was also fully patched at the time it was listed, according to security researcher Kevin Beaumont, who checked our findings.

However, August 2022 was the same month that hackers began exploiting a then-unpatched zero-day flaw affecting Exchange on-premise servers called ProxyNotShell, which can be abused to gain full control of an email server. At the time, there were no patches for ProxyNotShell until months later in November 2022, Beaumont said. Exploitation of ProxyNotShell was widespread across the internet.

A key question will be if the hackers gained access to the Commission’s network and then its email server, or if the email server was compromised first and used to pivot and gain access to the Commission’s network. It’s a missing detail that could be important in understanding how the cyberattack was carried out.

Why did it take nine months to go public?

The Commission confirmed that it reported the hack 🖍️ to the Information Commissioner’s Office within the statutory 72 hours from the time of initial discovery of a cyberattack as required by U.K. data protection law.

The big question is why it took the Electoral Commission nine months to tell the public — whose information was ultimately affected — about the cyberattack. The Commission declined to comment, citing the ICO’s ongoing investigation. It’s also unclear why the nine-month delay was permitted by the ICO, which declined to comment when reached by TechCrunch.

The Commission said that it had to take “several steps” 🖍️ before it could make the incident public, such as expelling the hackers from its systems, assess the damage, and put in place new security measures to prevent a similar attack.

Those nine months of silence will likely face considerable scrutiny from those investigating the incident.

More TechCrunch

Ahead of the AI safety summit kicking off in Seoul, South Korea later this week, its co-host the United Kingdom is expanding its own efforts in the field. The AI…

UK opens office in San Francisco to tackle AI risk

Companies are always looking for an edge, and searching for ways to encourage their employees to innovate. One way to do that is by running an internal hackathon around a…

Why companies are turning to internal hackathons

Featured Article

I’m rooting for Melinda French Gates to fix tech’s broken ‘brilliant jerk’ culture

Women in tech still face a shocking level of mistreatment at work. Melinda French Gates is one of the few working to change that.

11 hours ago
I’m rooting for Melinda French Gates to fix tech’s  broken ‘brilliant jerk’ culture

Blue Origin has successfully completed its NS-25 mission, resuming crewed flights for the first time in nearly two years. The mission brought six tourist crew members to the edge of…

Blue Origin successfully launches its first crewed mission since 2022

Creative Artists Agency (CAA), one of the top entertainment and sports talent agencies, is hoping to be at the forefront of AI protection services for celebrities in Hollywood. With many…

Hollywood agency CAA aims to help stars manage their own AI likenesses

Expedia says Rathi Murthy and Sreenivas Rachamadugu, respectively its CTO and senior vice president of core services product & engineering, are no longer employed at the travel booking company. In…

Expedia says two execs dismissed after ‘violation of company policy’

Welcome back to TechCrunch’s Week in Review. This week had two major events from OpenAI and Google. OpenAI’s spring update event saw the reveal of its new model, GPT-4o, which…

OpenAI and Google lay out their competing AI visions

When Jeffrey Wang posted to X asking if anyone wanted to go in on an order of fancy-but-affordable office nap pods, he didn’t expect the post to go viral.

With AI startups booming, nap pods and Silicon Valley hustle culture are back

OpenAI’s Superalignment team, responsible for developing ways to govern and steer “superintelligent” AI systems, was promised 20% of the company’s compute resources, according to a person from that team. But…

OpenAI created a team to control ‘superintelligent’ AI — then let it wither, source says

A new crop of early-stage startups — along with some recent VC investments — illustrates a niche emerging in the autonomous vehicle technology sector. Unlike the companies bringing robotaxis to…

VCs and the military are fueling self-driving startups that don’t need roads

When the founders of Sagetap, Sahil Khanna and Kevin Hughes, started working at early-stage enterprise software startups, they were surprised to find that the companies they worked at were trying…

Deal Dive: Sagetap looks to bring enterprise software sales into the 21st century

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI moves away from safety

After Apple loosened its App Store guidelines to permit game emulators, the retro game emulator Delta — an app 10 years in the making — hit the top of the…

Adobe comes after indie game emulator Delta for copying its logo

Meta is once again taking on its competitors by developing a feature that borrows concepts from others — in this case, BeReal and Snapchat. The company is developing a feature…

Meta’s latest experiment borrows from BeReal’s and Snapchat’s core ideas

Welcome to Startups Weekly! We’ve been drowning in AI news this week, with Google’s I/O setting the pace. And Elon Musk rages against the machine.

Startups Weekly: It’s the dawning of the age of AI — plus,  Musk is raging against the machine

IndieBio’s Bay Area incubator is about to debut its 15th cohort of biotech startups. We took special note of a few, which were making some major, bordering on ludicrous, claims…

IndieBio’s SF incubator lineup is making some wild biotech promises

YouTube TV has announced that its multiview feature for watching four streams at once is now available on Android phones and tablets. The Android launch comes two months after YouTube…

YouTube TV’s ‘multiview’ feature is now available on Android phones and tablets

Featured Article

Two Santa Cruz students uncover security bug that could let millions do their laundry for free

CSC ServiceWorks provides laundry machines to thousands of residential homes and universities, but the company ignored requests to fix a security bug.

2 days ago
Two Santa Cruz students uncover security bug that could let millions do their laundry for free

TechCrunch Disrupt 2024 is just around the corner, and the buzz is palpable. But what if we told you there’s a chance for you to not just attend, but also…

Harness the TechCrunch Effect: Host a Side Event at Disrupt 2024

Decks are all about telling a compelling story and Goodcarbon does a good job on that front. But there’s important information missing too.

Pitch Deck Teardown: Goodcarbon’s $5.5M seed deck

Slack is making it difficult for its customers if they want the company to stop using its data for model training.

Slack under attack over sneaky AI training policy

A Texas-based company that provides health insurance and benefit plans disclosed a data breach affecting almost 2.5 million people, some of whom had their Social Security number stolen. WebTPA said…

Healthcare company WebTPA discloses breach affecting 2.5 million people

Featured Article

Microsoft dodges UK antitrust scrutiny over its Mistral AI stake

Microsoft won’t be facing antitrust scrutiny in the U.K. over its recent investment into French AI startup Mistral AI.

3 days ago
Microsoft dodges UK antitrust scrutiny over its Mistral AI stake

Ember has partnered with HSBC in the U.K. so that the bank’s business customers can access Ember’s services from their online accounts.

Embedded finance is still trendy as accounting automation startup Ember partners with HSBC UK

Kudos uses AI to figure out consumer spending habits so it can then provide more personalized financial advice, like maximizing rewards and utilizing credit effectively.

Kudos lands $10M for an AI smart wallet that picks the best credit card for purchases

The EU’s warning comes after Microsoft failed to respond to a legally binding request for information that focused on its generative AI tools.

EU warns Microsoft it could be fined billions over missing GenAI risk info

The prospects for troubled banking-as-a-service startup Synapse have gone from bad to worse this week after a United States Trustee filed an emergency motion on Wednesday.  The trustee is asking…

A US Trustee wants troubled fintech Synapse to be liquidated via Chapter 7 bankruptcy, cites ‘gross mismanagement’

U.K.-based Seraphim Space is spinning up its 13th accelerator program, with nine participating companies working on a range of tech from propulsion to in-space manufacturing and space situational awareness. The…

Seraphim’s latest space accelerator welcomes nine companies

OpenAI has reached a deal with Reddit to use the social news site’s data for training AI models. In a blog post on OpenAI’s press relations site, the company said…

OpenAI inks deal to train AI on Reddit data

X users will now be able to discover posts from new Communities that are trending directly from an Explore tab within the section.

X pushes more users to Communities