Home hero1

ICO reprimands Hackney Council after major cyber attack (and council denies any fault!)

When Jon Baines – Senior Data Protection Specialist at Mishcon de Reya LLP, Chair of NADPO.co.uk. and writer of  the blog Informationrightsandwrongs.com – says something is “extraordinary”, you’d better believe I am listening!

(In case you haven’t come across Jon’s content, you can find him here on LinkedIn.)

So what was so extraordinary?

The official response from London Borough of Hackney to the ICO’s conclusion of their investigation into a major cyber attack suffered by the Hackney council in 2020.

First, a little background. 

In 2020, as the whole world was reeling from the start of the Covid-19 pandemic, and global lockdown, some nasty pieces of work found it was a great time to wreak even more havoc, by running cyber attacks on already distracted and busy organisations.

One such organisation struck in 2020 was the London Borough of Hackney. As explained by the ICO:

“In October 2020, hackers attacked the London Borough of Hackney (LBoH) systems – accessing, encrypting, and in some instances exfiltrating records containing personal data… 

“Some of the data which was encrypted was also exfiltrated by the attackers…

“The hackers encrypted the data and then deleted 10% of the council’s backup before the council managed to intervene. The cyber-attack also resulted in LBoH systems being disrupted for many months with, in some instances, services not being back to normal service until 2022.”

After a lengthy investigation, and two sets of representations from LBoH to the ICO, the “enforcement action” taken by the ICO is a reprimand.

Yep, just a reprimand. You would be forgiven for thinking LBoH has got off lightly and would be rather grateful.

Especially as the published reprimand makes it clear that mistakes were made and the way the attacker accessed LBoH’s systems should have been foreseeable and prevented.

However, this is the “extraordinary” part of the story.

An unnamed “spokesperson for Hackney Council” has today published their response on the LBoH website, starting with:

“While we welcome the ICO completing its investigation, we maintain that the Council has not breached its security obligations. We consider that the ICO has misunderstood the facts and misapplied the law with respect to the issues in question, and has mischaracterised and exaggerated the risk to residents’ data.”

I’m going to say part of that again, as it really is quite surprising – “we maintain that the Council has not breached its security obligations.”

Let’s say the mystery spokesperson is right, and they weren’t lacking in security (stay with me) – was there anything else they could have done to decrease the risk of harm to individuals?

The data is described by the ICO as:

“The encrypted data included data on residents that revealed their racial or ethnic origin, religious beliefs, sexual orientation, health data, economic data, criminal offence data, and other data including basic personal identifiers such as names and addresses.”  

I wonder what the LBoH was doing with the special categories personal data – ethnicity, religious beliefs, and sexual orientation in particular – that was so important and necessary, that made it worth risking having it leaked to/by a cyber attacker?

While the LBoH has escaped a fine, or monetary penalty, I can’t imagine they have retained the trust of their residents, and we can’t quantify the cost to individuals of the stress and potential harm of having their personal data exposed.

May this be a warning to all organisations who feel compelled to collect “EDI data” (attached to individuals’ records especially) that the almost unseen fines are not the only risk here, and not even the biggest risk.

You need a damn good justification to even be asking those questions, and if that justification is “monitoring and maintaining/improving equality of opportunity and treatment” as allowed for under the Data Protection Act 2018, there are several actions to take for you to be collecting and using that data lawfully. And I am NOT talking about data security here (although of course, that is crucial, but it’s not the first consideration, by a long way!)

For more information on the legal considerations of collecting EDI data, check out the EDI data collection Board Paper or email me about running an EDI Workshop (clare@clarecpdataprotection.com)

Join the conversation about this case on the Forum.