Site navigation

UK Electoral Register Reveals it Suffered “Complex Cyber-Attack”

Elizabeth Greenberg

,

uk electoral cyber-attack
The cyber-attack was first identified in October 2022, but took place in August 2021. 

The UK Electoral Commission revealed that it suffered a “complex cyber-attack” which first occurred in August 2021, and was identified in October 2022.

During the cyber-attack, perpetrators had access to the Electoral Commission’s servers which held their email and control systems, as well as copies of the electoral registers.

While it remains unclear how many people may have been affected by the breach, the commission estimates that the register holds the data of around 40 million people each year.

According to the release, these registers held at the time of the cyber-attack included the name and address of anyone in the UK who was registered to vote between 2014 and 2022, as well as the names of those registered as overseas voters.

Information in the Electoral register entries – which threat actors had access to – includes: names, home addresses in register entries, and the date on which a person achieved voting age that year.

The addresses of overseas voters were not accessible on the system that was breached.

Personal data contained in the email system of the Commission included: names, personal and business emails, home addresses if included in a webform or email, telephone numbers, content of the webform and email that may contain personal data, and any personal images sent to the Commission.

The Commission said that the information threat actors may have accessed is not ‘high risk’ in it of itself, but combined with other publicly available data, could be used to infer behavioral patterns or identify and profile individuals.

Further, the Commission insisted that the cyber-attack did not effect the election process.


Recommended reading


“The attack has not had an impact on the electoral process, has not affected the rights or access to the democratic process of any individual, nor has it affected anyone’s electoral registration status,” the Commission said in release about the incident.

For those working within the Commission, the email servers breached were also unlikely to present a “high risk” to individuals, unless they sent sensitive or personal information.

“Information related to donations and/or loans to registered political parties and non-party campaigners is held in a system not affected by this incident,” the release stated.

While the Commission says that no immediate action needs to be taken – they have since stopped the breach on their system – they do urge those who were registered to vote between 2014 and 2022 to “remain vigilant for unauthorised use or prelease of their personal data.”

The release made no mention of any suspected threat actors or the method used to access the system.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data