Hazard

Reprimands · Central government

The Electoral Commission

No fineReprimands
Root cause Unpatched or unsupported software A known vulnerability was left unfixed, or the software was past end of support. The most directly preventable cause on this list.

What happened

Reprimand issued to the Electoral Commission in respect of Articles 5(1)(f) and 32(1)(b). Between 24 August 2021 and 27 October 2022, a threat actor had access to the Electoral Commission’s systems and was able to access personal data held as part of the Electoral Register. This incident impacted approximately 40,000,000 individuals, and the initial access was gained via several unpatched software vulnerabilities. The investigation highlighted that appropriate technical and organisational measures were not in place at the time of the breach.

Summarised from the notice published by the ICO on 9 May 2024. Read the original notice — it is the authoritative version.

The other end of this

This action came down to software left unfixed. These vulnerabilities are confirmed exploited and already past their remediation deadline.

All exploited vulnerabilities →