Compromised.
Have I Been Pwned.com is a website that allows Internet users to check if their personal data has been compromised by data breaches. The service collects and analyzes dozens of database dumps and pastes containing information about hundreds of millions of leaked accounts, passwords and credit card details for example, and allows users to search for their own information by entering their username or email address.
In late August 2017, 700m email addresses, as well as a large number of passwords, were leaked publicly thanks to a mis-configured spambot, in one of the largest data breaches ever. Just to put that number – 700 million – into a sense of perspective for you, that was at the time – almost one address for every single man, woman and child in all of Europe.
-
“A “data breach” is an incident where a site’s data has been illegally accessed by hackers and then the data being released publicly. The types of data that are usually compromised are – email addresses, passwords, credit cards etc – this is why it is necessary and important to change one’s passwords regularly.
Now local government organisation such as Shepway District Council handle data from the general public and its contractors by necessity. Therefore it is imperative that members of that organisation are well versed in online security practices in order to keep the public’s data secure, as well as commercially sensitive data too. With services available to identify compromises in security freely available online, such as haveibeenpwnd.com we hope they use it or an equivalent regularly.
It is known that both Cllr David Monk’s and the Chief Executive – Alistair Stewart’s (pictured above) SDC email accounts – were both part of a data breach in August 2017, in which some of their SDC information was harvested by a “spambot” called Onliner Spambot
Such incidents raises some very serious questions:
-
Did Councillor Monk and Mr Stewart know about the breach?
-
Did Councillor Monk, Mr Stewart raise the alarm about suspect emails being sent to them?
-
Did they report any breach to their IT personnel?
-
Did the IT personnel identify it on their system?
-
What steps if any were taken subsequently by SDC, if Cllr Monk/Mr Stewart informed the IT personnel?
-
Was/has any data lost due to the breach?
Absolutely wonderful, well done for flagging this up.