Cyber fears as HMRC declares 17 serious data breaches to ICO
Her Majesty’s Revenue and Customs (HMRC) has reported a total of 17 serious data breaches to the Information Commissioner’s Office (ICO) over a 15 month period, from January 2020 to March 2021.
The data, analysed by niche litigation practice Griffin Law, was revealed in HMRC’s recently published Annual Report and Accounts.
According to the report, a total of 3,017 people were potentially affected by personal data-related incidents.
In the largest incident, 1,023 people were potentially impacted when a HMRC staffer used personal information to make changes to customer records on HMRC systems without authorisation.
The most alarming infringement saw a HMRC employee caught accessing an internal system to locate his estranged wife and children, potentially affecting a total of 4 people.
In another family related data breach, a customer received details about his former partner when making a SAR (Suspicious Activity Report) request for information, potentially impacting the customer and his ex-partner.
During an office relocation, a customer’s locked pedestal desk was forced open, resulting in personal identifiers such as ethnic origin and religious beliefs being exposed.
The most frequent breach involved HMRC staffers using personal information to alter customer records on HMRC systems. This occurred on 11 separate occasions, potentially impacting a combined total of 2,999 people.
HMRC stated in the report that they have learnt lessons from the incidents and are using them to review and strengthen their customer identity and authentication process.
In spite of the breaches, HMRC stated in the report: “Protecting customer data is important to us and we monitor our processes continually to prevent recurrences. In addition, HMRC is delivering enhanced data security, governance and reporting across the department.”
A number of other personal data-related breaches were revealed but were not required to be reported to the Information Commissioner, instead being recorded centrally within the department.
Donal Blaney, Founder of Griffin Law commented on the breaches, stating: “HMRC wields draconian powers, and is increasingly out of control. This is further evidence that HMRC needs to be reined in. They think they’re above the law. They’re not.
Such abuse of its powers, and such criminality, should be investigated to the fullest extent possible by the Information Commissioner and the police if taxpayers are to retain any confidence in HMRC” he continued.
Security specialist Edward Blake, Area Vice President EMEA for Absolute Software said: “HMRC stores and manages countless quantities of sensitive data on a daily basis. This marks HMRC and similar public sector organisations and large institutions as prime targets on the radar of opportunistic cyber attackers. Large organisations and governmental departments must be privy to this fact, and employ the right protection and security tools to protect customers’ data which is at risk.
“Today there are more access points than ever before for the cyber criminal, and organisations must defend against all possible angles. This includes protecting everything from firmware and devices, to apps and network connections. Adopting ‘Zero Trust’ protocols is one of the most effective ways of stopping bad actors in their tracks, and ensuring that a breach in the system does not necessarily equate to a breach of data. Also, leveraging self-healing technologies to detect and repair unhealthy applications and connections for optimal security and experience is key to boosting network and application security, and negating risk.”
Tim Sadler, CEO and co-founder of Tessian, commented: “The majority of today’s data breaches are caused by people. Why? Because people make mistakes, break the rules and can be hacked. As employees handle and control more data than ever before, organisations must take steps to protect data from incidents caused by people if they’re ever going to stop breaches.”
More in Tech, IT & Comms
Storm Internet confirmed as B4’s Official Managed Web Hosting Partner
B4 announce their ‘Official Managed Web Hosting’ Partner – a multi award-winning organisation and long-standing B4 Member – Storm Internet. The partnership will see Storm Internet hosting B4’s website and becoming one of the Oxfordshire Business Summit sponsors.
The Ultimate Guide to Office Relocation – 9 -The Move Day...
The Move Day & Post-Move Actions Moving office is disruptive, so you need to be doing everything you can to mitigate relocation mistakes. Above all, allocate plenty of time for the move and don’t be too ambitious with what can be achieved in a day or two! If you have followed the guidance from our […]
The Ultimate Guide to Office Relocation – 8 – IT Specific...
IT-specific Considerations for an Office Move Let us present a list of things that we at Flex IT are regularly asked by clients who are moving offices. In some cases, advice is sought, in others, we are assigned responsibility for managing the IT side of relocation. Firstly, it’s very important to give your IT team […]
From this author
Pioneering US-based Canoo Inc’s versatile electric vehicle experience arrives at Bicester...
Canoo Inc, a US-based company which has created revolutionary multi-purpose platforms and digital ecosystems that are transforming the automotive industry for the entire vehicle lifecycle, has selected Bicester Motion, the 444-acre future mobility estate in Bicester, Oxfordshire, as its UK commercial operations and activation centre.
The Wesley Hotel Euston launches festive dining offering
Celebrate the festive season with delicious food and great company at the centrally located The Wesley Euston hotel, bar and kitchen as it announces two Christmas menus, each tailored to a different dining experience.
Ingram ‘incredibly proud’ after going down fighting in Brands Hatch decider
There was no fairytale ending for Tom Ingram in the 2024 British Touring Car Championship finale at Brands Hatch last weekend (5-6 October), but the former champion went down fighting with a characteristically heroic performance as circumstances cruelly conspired against him.