Site navigation

HMRC has Reported 17 Major Data Breaches to the ICO This Year

David Paul

,

HMRC data breaches
More than 3,000 people may have been affected by Her Majesty’s Revenue and Customs (HMRC) personal data-related incidents over a 15-month period.

New data has revealed that a total of 17 serious HMRC data breaches were reported to the Information Commissioner’s Office (ICO) between January 2020 and March 2021.

Analysed by litigation practice Griffin Law, the collected data was revealed in HMRC’s recently published Annual Report and Accounts.

The report disclosed that a total of 3,017 people were potentially affected by personal data-related incidents over the period.

In the largest recorded incident, 1,023 people may have been impacted after personal information was used by unauthorised third parties to access and make changes to customer records.

Additionally, in a particularly alarming incident, an employee was caught accessing an internal system to locate his estranged wife and children, potentially affecting four people, HMRC said. The staff member was subsequently dismissed.

A customer also received details about his former partner when making a Suspicious Activity Report information request, potentially impacting a customer and his ex-partner.

Commenting on the report, Donal Blaney, Founder of Griffin Law, said: “HMRC wields draconian powers, and is increasingly out of control. This is further evidence that HMRC needs to be reined in. They think they’re above the law. They’re not.

“Such abuse of its powers, and such criminality, should be investigated to the fullest extent possible by the Information Commissioner and the police if taxpayers are to retain any confidence in HMRC.”

The most frequently mentioned breach involved personal information being used to alter customer records. This supposedly occurred 11 times over the period, potentially impacting 2,999 people. These incidents involved criminals obtaining personal information from their victims through a variety of methods, including breaches of other organisations’ security, and using that to access customer records.

In the previous period, between 2019 and 2020, around 23,000 people were affected by 11 breaches reported by HMRC. The most serious incident saw national insurance letters with incorrect details for 16-year-olds sent out.

The HMRC cyber breaches could have revealed previous birth names, the identity of adopted children, as well as the identity of transgender children.

HMRC stated in its latest report that they have “learnt lessons” from the incidents and are using them to “review and strengthen” customer identity and authentication process.

Despite the breaches, HMRC said in the report: “Protecting customer data is important to us and we monitor our processes continually to prevent recurrences. In addition, HMRC is delivering enhanced data security, governance and reporting across the department.”


Recommended


Security specialist Edward Blake, Area Vice President EMEA for Absolute Software said: “HMRC stores and manages countless quantities of sensitive data on a daily basis. This marks HMRC and similar public sector organisations and large institutions as prime targets on the radar of opportunistic cyber attackers.

“Large organisations and governmental departments must be privy to this fact and employ the right protection and security tools to protect customers’ data which is at risk.

“Today there are more access points than ever before for the cybercriminal, and organisations must defend against all possible angles. This includes protecting everything from firmware and devices to apps and network connections.”

Blake added: “Adopting ‘Zero Trust’ protocols is one of the most effective ways of stopping bad actors in their tracks and ensuring that a breach in the system does not necessarily equate to a breach of data.

“Also, leveraging self-healing technologies to detect and repair unhealthy applications and connections for optimal security and experience is key to boosting network and application security, and negating risk.”

Tim Sadler, CEO and co-founder of Tessian, added: “The majority of today’s data breaches are caused by people. Why? Because people make mistakes, break the rules and can be hacked.

“As employees handle and control more data than ever before, organisations must take steps to protect data from incidents caused by people if they’re ever going to stop breaches.”

An HMRC spokesperson said: “We take the protection of our customers’ information extremely seriously and continually monitor our systems and data to make sure that information is safe.

“In some of these incidents, customer accounts were accessed using personal data that criminals could have obtained through a variety of methods, including breaches of other organisations’ security. We have established processes for when a customer record is affected by fraudulent activity by a criminal third party.

“We deal with millions of customers every year and tens of millions of paper and electronic interactions. Security and privacy are at the heart of our work. We investigate all security incidents, taking immediate action to reduce the possibility of recurrence.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

We will keep you up to date on the pivotal issues impacting the sector and let you know about key upcoming events to ensure that you don’t miss out on what’s going on across the Scottish tech community.

Click here to subscribe.

David Paul

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data