Security flaw in Tory conference app leaks attendee data

Senior Conservative figures such as Boris Johnson and Michael Gove had their accounts hacked after attendees guessed their email addresses

Glum Boris

A security flaw in the official Conservative Party conference app made its users' private data accessible to anyone with just an email address.

Third parties who either had or could work out a user's email address could access their accounts. Once logged in, they could see private information, such as phone numbers, or make changes to personal details and make them public.

Advertisement - Article continues below

Cabinet minister Michael Gove and former foreign secretary Boris Johnson both had their accounts hacked, with the latter's profile picture being changed to one featuring a pornographic image.

The leak also included attendees, such as members of the press. Guardian journalist Dawn Foster was one of the first to report the breach and tweeted a photo of a statement she received from the app.

"The technical error was resolved within 30 minutes after being brought to our attention, the Conference App is now functioning securely and we have made an initial data breach report to the Information Commissioner's Office (ICO)," a Tory spokesman said.

"But it's not good enough that people's data may have been made available and we are disappointed that we have been let down by a third party supplier - CrowdComms."

CrowdComms is an Australian company and it posted an apology to the Tory party saying of the breach: "it is likely that it affected a very small proportion of attendees."

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Commenting on the breach, Mark Noctor, VP at Arxan Technologies, said that while the Conservative party may have stopped the leak of sensitive data, it raises concerns over the government's suitability in this age of data privacy.

"As the party of government, the Tories are meant to be passing and enforcing laws, this would appear to be a breach of GDPR law, rising to the fore whether enough has really been done to ensure data privacy," he said.

Both the Tory party and CrowdComms have made the ICO aware of the breach. In a statement, the ICO said: "We are aware of an incident involving a Conservative Party conference app and we will be making enquiries with the Conservative party.

"Organisations have a legal duty to keep personal data safe and secure. Under the GDPR they must notify the ICO within 72 hours of becoming aware of a personal data breach if it could pose a risk to people's rights and freedoms."

Featured Resources

Successful digital transformations are future ready - now

Research findings identify key ingredients to complete your transformation journey

Download now

Cyber security for accountants

3 ways to protect yourself and your clients online

Download now

The future of database administrators in the era of the autonomous database

Autonomous databases are here. So who needs database administrators anymore?

Download now

The IT expert’s guide to AI and content management

Your guide to the biggest opportunities for IT teams when it comes to AI and content management

Download now
Advertisement

Recommended

Visit/security/cyber-security/355267/zoom-hires-ex-facebook-cso-to-boost-platform-security
cyber security

Zoom hires ex-Facebook CSO Alex Stamos to boost platform security

8 Apr 2020
Visit/security/vulnerability/355236/hp-support-assistant-flaws-leave-windows-devices-open-to-attack
vulnerability

HP Support Assistant flaws leave Windows devices open to attack

6 Apr 2020
Visit/security/cyber-security/355234/safari-bug-let-hackers-access-cameras-on-iphones-and-macs
cyber security

Safari bug let hackers access cameras on iPhones and Macs

6 Apr 2020
Visit/software/video-conferencing/355229/zoom-we-moved-too-fast
video conferencing

Zoom CEO admits company "moved too fast" as privacy issues mount

6 Apr 2020

Most Popular

Visit/mobile/mobile-phones/355239/microsofts-patent-design-reveals-a-mobile-device-with-a-third-screen
Mobile Phones

Microsoft patents a mobile device with a third screen

6 Apr 2020
Visit/server-storage/servers/355254/a-critical-flaw-in-350000-microsoft-exchange-remains-unpatched
servers

A critical flaw in 350,000 Microsoft Exchange remains unpatched

7 Apr 2020
Visit/software/video-conferencing/355257/taiwan-first-country-to-ban-zoom-amid-security-concerns
video conferencing

Taiwan becomes first country to ban Zoom amid security concerns

8 Apr 2020