logo

How the theft of 40M UK voter register records was entirely preventable

ID: 8c040723-9cc4-564e-a9f0-b1eb6dbf5dfb

STIX ID: report--8c040723-9cc4-564e-a9f0-b1eb6dbf5dfb

Feed Name: TechCrunch Security News

Threat Score
90/100

Date Published: 2024-08-03

Date Updated: 2026-04-23

Author: Zack Whittaker, Natasha Lomas

...
...

A preventable cyberattack on the U.K. Electoral Commission exploited unpatched ProxyShell vulnerabilities in a self-hosted Microsoft Exchange server during 2021–2022, allowing intruders to steal electoral register data for approximately 40 million people. The ICO reprimanded the Commission for basic security failings (patching and password management); the U.K. government later attributed the intrusion to China-affiliated actors, but the ICO did not issue a fine due to its public-sector enforcement policy and no evidence of data misuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.