Site navigation

Labour Party Data Made Inaccessible After Third Party Incident

Michael Behr

,

Labour Party Data
With details still scant, the Labour Party is working with other organisations to investigate the scale of the incident.

The Labour Party has seen “a significant quantity of Party data being rendered inaccessible” after a “cyber incident”.

The event occurred at a third party that handles its membership data. According to Labour, it was told about the incident on October 29th.

Labour noted that its own data systems had not been affected by the incident, and that it is working closely with the third party to find out what happened.

While the nature and scope of the data has not yet been revealed, Labour said that it includes information provided to the party by its members, registered and affiliated supporters, and others who have provided information.

“As soon as the Party was notified of these matters, we engaged third-party experts and the incident was immediately reported to the relevant authorities,” the Labour Party statement said.

The party said that its own investigation is currently ongoing. In addition, both the National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO) are investigating the incident. The National Crime Agency (NCA) has also been informed.

An NCSC spokesperson said: “We are aware of this issue and are working with the Labour Party to fully investigate and mitigate any potential impact.

“We would urge anyone who thinks they may have been the victim of a data breach to be especially vigilant against suspicious emails, phone calls or text messages and to follow the steps set out in our data breaches guidance.

“The NCSC is committed to helping organisations manage their cyber security and publishes advice and guidance on the NCSC website.”


Recommended


While the investigation is still ongoing, Labour warned that anyone who has provided data to the party will need to be vigilant against attempted phishing attacks or hacking. This includes suspicious emails, phone calls or text messages.

It also advised people to implement two-factor authentication (2FA) where possible to protect their online accounts from unauthorised access.

Commenting on the news, lead security awareness advocate at KnowBe4 Javvad Malik: “Not many details are publicly available at the moment, but all signs point towards this being a ransomware attack.

“The hard part about ransomware attacks is depending on who the attacker is, there is no way of knowing how long the criminals were in the systems and whether they made a copy of all the data before deploying the ransomware.

“The backups can help recover impacted systems, but if data was taken then the problem becomes much more difficult to contain. It’s why organisations should not neglect to implement controls that prevent such attacks from being successful in the first place – this involves looking at root causes of infection which often boils down to social engineering attacks, unpatched software, or poor credentials with layers put into place for defence against these kinds of cyberattacks.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

We will keep you up to date on the pivotal issues impacting the sector and let you know about key upcoming events to ensure that you don’t miss out on what’s going on across the Scottish tech community.

Click here to subscribe.

Michael Behr

Senior Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data