Reprimands · Central government
The Electoral Commission
What happened
Reprimand issued to the Electoral Commission in respect of Articles 5(1)(f) and 32(1)(b). Between 24 August 2021 and 27 October 2022, a threat actor had access to the Electoral Commission’s systems and was able to access personal data held as part of the Electoral Register. This incident impacted approximately 40,000,000 individuals, and the initial access was gained via several unpatched software vulnerabilities. The investigation highlighted that appropriate technical and organisational measures were not in place at the time of the breach.
Summarised from the notice published by the ICO on 9 May 2024. Read the original notice — it is the authoritative version.
The other end of this
This action came down to software left unfixed. These vulnerabilities are confirmed exploited and already past their remediation deadline.
- CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability Check Point · SmartConsole
- CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft · SharePoint
- CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability WordPress · Core
- CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability Langflow · Langflow
- CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability DD-WRT · DD-WRT