UK Electoral Commission slapped for basic cybersecurity fails
ID: 4bed611b-a9ec-5166-bb37-6c4211234ed1
STIX ID: report--4bed611b-a9ec-5166-bb37-6c4211234ed1
Feed Name: The Register (Security)
The ICO has issued a formal reprimand to the UK's Electoral Commission after a 2021 breach of its Microsoft Exchange server (linked to ProxyShell exploitation) allowed attackers—attributed by the UK to Chinese state-sponsored actors—to access names and home addresses of roughly 40 million voters for about 13 months. The report highlights failures in patch management, use of default/weak passwords, long detection time, and deployment of web shells; the Commission has since implemented remedial security measures and an infrastructure modernization plan.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
