Tag Archive for: watchdog

Watchdog says it won’t give in to hackers’ blackmail


The Consumer Council on Friday confirmed it has been the victim of a hacking attack, saying it won’t pay a blackmail demand and will only find out exactly what data has been stolen when it gets leaked on the internet.

The watchdog said its computer system was hacked on Wednesday and was told to pay a ransom of US$700,000 to prevent the stolen data from being made public.

The hackers are offering a US$200,000 discount if the ransom is paid by 11.20pm on Saturday.

The attack comes just weeks after government-owned Cyberport also fell prey to hackers who stole personal information on various individuals linked to the technology park.

The Consumer Council said it wasn’t sure what data has been stolen from its system, but it could include ID and phone numbers of current and former staff, their relatives, as well as job applicants.

The watchdog said the breach might also affect some 8,000 subscribers to its CHOICE magazine.

“Because we will definitely not pay the ransom, we will probably need to wait after the ransom deadline and the attackers leak the stolen data to determine what data has exactly been stolen,” said Gilly Wong, the council’s chief executive.

At a press briefing, chairman Clement Chan said the hacking incident has caused disruption to the council’s services.

“The attack has resulted in almost 80 percent damage of the computer system, causing disruption to its hotline services and update of price comparison tools,” said Chan.

“The council has taken immediate action to strengthen the security measures of the system to prevent further attacks by the hacker, whilst appointing a forensic expert immediately to conduct investigations. Hotline services have currently resumed after emergency repairs.”

The council said it would reach out to potential victims of the breach in the next few days, adding that it has also reported the incident to the police and the privacy watchdog.

Source…

UK election watchdog failed to discover system hack for 15 months


The UK’s Electoral Commission today announced it suffered a cyberattack in August 2021, with attackers gaining access to registers that contained the names and addresses of anyone in the UK who was registered to vote between 2014 and 2022, as well as the names of those registered as overseas voters.

In a statement issued by the Electoral Commission via its website, the election watchdog said that although attackers first gained access to electoral registers and the commission’s email system in August, the hack wasn’t identified until October  2022, when the electoral body became aware of a suspicious pattern of log-in requests being made to its systems.

The commission said while it is “not able to know conclusively” what information had been accessed, the personal data most likely to have been accessible includes names, addresses, email addresses, and any other personal data sent to the commission by email or held on the electoral registers. Due to large parts of the UK’s electoral system still being paper based, however, “it would be very hard to use a cyber-attack to influence the [electoral] process.” The Commission also sought reassure those that might have been affected by the breach by noting that the hack will not impact an individual’s ability to take part in the democratic process or affect their current registration status or eligibility to vote.

“We regret that sufficient protections were not in place to prevent this cyber-attack. Since identifying it we have taken significant steps, with the support of specialists, to improve the security, resilience, and reliability of our IT systems,” Shaun McNally, the Electoral Commission chief executive, said in a statement.

In line with requirements under the law, McNally said the Electoral Commission notified the Information Commissioner’s Office (ICO) within 72 hours of identifying the breach and the ICO is currently investigating the incident.

“The Electoral Commission has contacted us regarding this incident and we are currently making enquiries,” a spokesperson for the ICO said in a statement. “We recognise this news may cause alarm to those who are worried they may be affected and we want to…

Source…

Capita hack: 90 organisations report data breaches to watchdog



Around 90 organisations have reported breaches of personal data held by Capita, the outsourcing giant, according to an privacy watchdog. The company suffered a cyber attack in March this year and it …

Source…

Capita: Watchdog warns pension funds over data after hack



The Pensions Regulator has asked trustees responsible for funds that use Capita as an administrator to assess whether clients’ data is at risk. After the hack in late March, personal information held …

Source…