UK govt links 2021 Electoral Commission breach to Exchange server

By Sergiu Gatlan, Bleeping Computer

The United Kingdom's Information Commissioner's Office (ICO) revealed today that the Electoral Commission was breached in August 2021 because it failed to patch its on-premise Microsoft Exchange Server against ProxyShell vulnerabilities.

In March, the U.K. National Cyber Security Centre (NCSC) attributed the UK Electoral Commission breach to a Chinese state-backed threat actor.

Tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207, these security flaws were chained to hack into the commission's Exchange Server 2016 and deploy web shells, which allowed the attackers to gain persistence after installing web shells and backdoors.

While Microsoft released security updates in May 2021 that fixed the ProxyShell vulnerability chain, the commission failed to patch its systems promptly, exposing them to attacks.

The attack and the deployed malware were discovered on October 28, 2021, when an employee found that the Commission's Exchange server was being used to send spam emails.

During the breach, the Chinese hackers gained access to the personal information of around 40 million people, including their names, home addresses, email addresses, and phone numbers.

While the commission downplayed the impact, saying "much of it is already in the public domain," only voters' names and addresses are publicly available in the U.K. open register.

"Our investigation found that the Electoral Commission did not have appropriate security measures in place to protect the personal information it held," the ICO said.

"The Electoral Commission also did not have sufficient password policies in place at the time of the attack, with many accounts still using passwords identical or similar to the ones originally allocated by the service desk."



Comments

Popular posts from this blog

Why remote desktop tools are facing an onslaught of cyber threats

Ransomware gang starts leaking alleged stolen Change Healthcare data

Notepad++ wants your help in "parasite website" shutdown