Elections watchdog apologises after hack left voters’ details exposed

8 August 2023, 19:34

Ballot box
Ballot box. Picture: PA

Electoral Commission head Shaun McNally said it would be very hard to use a cyber-attack to influence the democratic process.

Details of tens of millions of voters could have been accessed by hackers who targeted the elections watchdog.

The Electoral Commission said there was little risk of “hostile actors” being able to influence the outcome of a vote, but apologised for the breach in its systems.

The hack, which was publicly confirmed on Tuesday, allowed the attackers to access reference copies of electoral registers containing the names and addresses of people registered to vote between 2014 and 2022.

The attack was identified in October 2022, but the hackers had first been able to access the commission’s systems in August 2021.

Shaun McNally, the Electoral Commission’s chief executive, said: “The UK’s democratic process is significantly dispersed and key aspects of it remain based on paper documentation and counting.

“This means it would be very hard to use a cyber-attack to influence the process.

“Nevertheless, the successful attack on the Electoral Commission highlights that organisations involved in elections remain a target, and need to remain vigilant to the risks to processes around our elections.”

He said significant measures had been taken to improve security on the commission’s IT systems.

“We know which systems were accessible to the hostile actors, but are not able to know conclusively what files may or may not have been accessed,” he said.

“While the data contained in the electoral registers is limited, and much of it is already in the public domain, we understand the concern that may have been caused by the registers potentially being accessed and apologise to those affected.”

The hackers were able to access reference copies of the electoral registers, held by the commission for research purposes and to enable permissibility checks on political donations.

The registers held at the time of the cyber-attack include the name and address of anyone in the UK who was registered to vote between 2014 and 2022, as well as the names of those registered as overseas voters.

But they did not include the details of those registered anonymously.

The register for each year holds the details of around 40 million individuals, which were accessible to the hostile actors, although this includes people on the open registers, whose information is already in the public domain.

The National Cyber Security Centre said it had provided the commission with expert advice and support.

A spokesman said: “Defending the UK’s democratic processes is a priority for the NCSC and we provide a range of guidance to help strengthen the cyber resilience of our electoral systems.”

The Information Commissioner’s Office said it was looking into the incident.

“We recognise this news may cause alarm to those who are worried they may be affected and we want to reassure the public that we are investigating as a matter of urgency,” a spokesman said.

“In the meantime, if anyone is concerned about how their data has been handled, they should get in touch with the ICO or check our website for advice and support.”

Labour’s deputy leader Angela Rayner said: “This deeply concerning attack serves as a reminder of the critical importance of Britain’s resilience to cyber-attacks.

“Our democracy is a foundation of our society and every effort must be made to protect it.

“This serious incident must be fully and thoroughly investigated so lessons can be learned.”

By Press Association

More Technology News

See more More Technology News

Sir Keir Starmer gesticulates as he delivers a speech at Google's London AI Campus

UK to go ‘all-in’ on AI as Starmer throws weight of Whitehall behind technology

Prime Minister Sir Keir Starmer gives a speech during a visit to Google's new AI Campus in Somers Town, north west London, on Wednesday November 27, 2024.

Starmer vows to make Britain ‘world-leader’ in AI to boost growth as private firms commit £14 billion to the industry

Peter Kyle answers a question while appearing on the BBC's Sunday with Laura Kuenssberg show

Tech giants must obey UK’s online safety laws, says minister

Peter Kyle

UK must not let AI ‘wash over our economy’, says Science Secretary

Online safety laws must constantly adapt along with tech, says minister

Online safety laws must constantly adapt along with tech, says minister following criticism from Molly Russell's father

Peter Kyle speaks to the press outside Broadcasting House in London

UK will not pit AI safety against investment in bid for growth, says minister

Molly Russell who took her own life in November 2017 after she had been viewing material on social media

UK going ‘backwards’ on online safety, Molly Russell’s father tells Starmer

Ellen Roome with her son Jools Sweeney

Bereaved mother: Social media firms ‘awful’ in search for answers on son’s death

A remote-controlled sex toy

Remote-controlled sex toys ‘vulnerable to attack by malicious third parties’

LG AeroCatTower (Martyn Landi/PA)

The weird and wonderful gadgets of CES 2025

Sinclair C5 enthusiasts enjoy the gathering at Alexandra Palace in London

Sinclair C5 fans gather to celebrate ‘iconic’ vehicle’s 40th anniversary

A still from Kemp's AI generated video

Spandau Ballet’s Gary Kemp releases AI generated music video for new single

DragonFire laser weapon system

Britain must learn from Ukraine and use AI for warfare, MPs say

The Pinwheel Watch, a smartwatch designed for children, unveiled at the CES technology show in Las Vegas.

CES 2025: Pinwheel launches child-friendly smartwatch with built in AI chatbot

The firm said the morning data jumps had emerged as part of its broadband network analysis (PA)

Millions head online at 6am, 7am and 8am as alarms go off, data shows

A mobile phone screen

Meta ends fact-checking on Facebook and Instagram in favour of community notes