NZ ministry knew of massive data breach

 

Chose not to act after informant sought cash reward.

Revelations that members of the public could access confidential documents from kiosks installed at a New Zealand government welfare agency has blown into a national scandal, with data from multiple agencies, corporations and citizens leaked.

As reported on iTnews earlier today, blogger Keith Ng was able to gain access to highly sensitive information - including invoices and personal contact data - from self-service kiosks installed by the New Zealand Work and Income welfare agency.

The data included invoices issued to the Ministry that featured information about children in state care.

The self-service kiosks were installed by the New Zealand Work and Income welfare agency just over a year ago as part of a staff reduction program and to provide jobseekers internet access to apply for jobs online.

Today it has been revealed that the anonymous source that tipped off journalists about the vulnerability had approached the Ministry last week, seeking a financial reward.

Ng speaks

iTnews spoke to the Wellington-based blogger, Keith Ng, who first broke the news about the massive privacy breach after being tipped off last Tuesday.

His source claimed to have been aware of the breach for a number of days and had also alerted the Ministry last week, seeking a financial reward.

Ng told iTnews he was unsure how well-known the issue was and whether it has already been exploited.

“It’s not something you would stumble upon [by accident],” Ng said.

"You need to sit there for around half an hour to work out what’s happening and to navigate the system," Ng said.

The kiosks, which run an old version of Windows, 2000 or XP, had some protections in place to prevent unauthorised access.

“You can’t click on things and can’t open Explorer (the Windows built-in file management tool),” Ng said.

However, the security restrictions were easily bypassed as the kiosks run a full version of Microsoft’s Office Productivity suite, including applications such as Excel and Word, Ng said.

“By using the Open File dialog, you had access to the applications’ file manager and could read files that way, as well as copy and move them,” Ng said.

Ng says the kiosks were Internet-connected with browsers that provided access to webmail, meaning confidential files could have easily been sent in that manner. The kiosks also featured USB access.

The biggest problem Ng faced in accessing the data was the slow network performance at WINZ.

“It took two and a half hours to copy 400Mbyte of data [to USB],” he said.

Ng stressed that he no longer possesses that data, after being advised by the Privacy Commissioner’s office to delete it. He also pointed out that files visible on the network via the kiosks are invoices and not social welfare records.

Even so, the invoices contained a great amount of identifying details about welfare clients. In fact, it was not even necessary in many cases to view the invoices to glean details of welfare clients. The file names visible on the network were long and descriptive, he said.

Ng also revealed that because MSD was handling the payment of invoices for the Canterbury Earthquake Recovery Authority (CERA), invoices for that government agency were also visible via the kiosks on a shared network drive.

This may take the breach beyond an issue of personal privacy and into the realm of commercial confidentiality, should information relating to ministry contractors be leaked.

Fairfax News reported that the minister for earthquake recovery, Gerry Brownlee, has confirmed that CERA information was shared with the MSD and may have been available to people using the kiosks.

Minister "mortified"

At a media conference in Wellington today, the cabinet minister for social development and employment, Paula Bennett, labelled the privacy breach as “completely and utterly unacceptable.”

“Significant mistakes were made,” Bennett said. A review of the MSD’s information systems will be held, with reference terms to be published as soon as possible.

Bennett apologised to the New Zealand public for the breach and said she was "mortified".

The chief executive of MSD, Brendan Boyle said at the same conference that the breach “is embarrassing” and that he would do everything to make sure it doesn’t happen again.

He also said that the MSD was alerted to the issue last week by an informant who told the ministry that he was working with a journalist.

The informant “was quite vague” and sought a reward for providing the information. Boyle said this was something the MSD would not offer.

Boyle said the ministry did not take action because the informant did not provide any further details.

The informant is thought to be the same person that tipped off Ng.

Ng told iTnews his source had access to the data as well, but assured him that it had been deleted. He wasnot aware of any one else with access to the data.

DiData implicated

The kiosks were built internally by the MSD and deployed by the Ministry with the help of systems integrators Dimension Data.

Boyle says the kiosks were for the public to use, and that no logins were required. He is checking if there is an audit trail that could reveal how much information has been leaked.

Boyle says that Dimension Data conducted security tests on the kiosks, but found no problems.

“I am grateful to Mr Ng for cooperating and keeping the information secure, handing it to the Privacy Commissioner," he said.

Boyle said that while it is "too soon to say", it is “certainly not my intention” to prosecute Ng for unauthorised computer access, which is illegal under NZ computer crimes legislation.

The New Zealand assistant privacy commissioner Katrine Evans said her office is very concerned about the breach and has already launched an investigation.

Copyright © iTnews.com.au . All rights reserved.


NZ ministry knew of massive data breach
Paula Bennett, NZ minister for social development and employment.
 
 
 
 
Top Stories
NBN Co could miss revised June fibre targets
Analysis: Cutting it fine in the race to the line.
 
Review: Sydney's Opal smartcard
It's no Oyster card.
 
Rackspace puts price premium on Aussie public cloud
At least 17 percent more compared to US instances.
 
 
Paula Bennett, NZ minister for social development and employment.
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Vivek Kundra on Australia's 'cloud last' policy
Bankwest builds continuous delivery capability
Bankwest builds continuous delivery capability
To automatically deploy test/dev sandboxes by mid-year.
Veterans' Affairs sets sights on modernisation
Veterans' Affairs sets sights on modernisation
Data safe with Human Services, CIO says.
Citi Australia drops platform customisations
Citi Australia drops platform customisations
Technology chief shifts focus from building to leveraging systems.
VicRoads restructures IT team
VicRoads restructures IT team
Department moves to align with industry benchmarks.
Zurich Australia extends IT team offshore
Zurich Australia extends IT team offshore
Malaysian staff served from Australian data centres.
Leigh Berrell - Utilities CIO of the Year
Leigh Berrell - Utilities CIO of the Year
Yarra Valley Water CIO Leigh Berrell accepts his Benchmark Award for Utilities CIO of the Year.
Wayne McMahon - Retail CIO of the Year
Wayne McMahon - Retail CIO of the Year
Domino's Pizza CIO Wayne McMahon accepts his Benchmark Award for Retail CIO of the Year.
Inside Perpetual's ongoing IT transformation
Inside Perpetual's ongoing IT transformation
CIO Jenny Levy discusses how outsourcing will help the firm "simplify, refocus and grow".
Managing Complexity - Defence's Daniel McCabe
Managing Complexity - Defence's Daniel McCabe
Daniel McCabe, Assistant Secretary of Australia's Department of Defence, provides the audience at the iTnews Data Centre Strategy Summit with a deep dive into the organisation's data centre consolidation program.
How Facebook designed the data centre from scratch - Marco Magarelli
How Facebook designed the data centre from scratch - Marco Magarelli
The full keynote by Facebook data centre architect Marco Magarelli at the Australian Data Centre Strategy Summit. Magarelli details the design considerations behind the social network's Prineville, Oregon; North Carolina and Luleå, Sweden data centres.
Modernising Legacy Data Centres - Telstra's Jon Curry
Modernising Legacy Data Centres - Telstra's Jon Curry
Telstra general manager of managed data centres Jon Curry guides the audience at the iTnews Australian Data Centre Summit through the build of the telco's Clayton, Victoria data centre.
NSW Government launches NABERS data centre rating tools
NSW Government launches NABERS data centre rating tools
Matthew Clark from the NSW Department of Environment guides facilties managers through the details of the new NABERS data centre energy rating tool at the Australian Data Centre Strategy Summit.
NABERS launch panel: Australian Data Centre Strategy Summit
NABERS launch panel: Australian Data Centre Strategy Summit
Matthew Clark (NSW Dept of Environment), Greg Boorer (Canberra Data Centres), Glenn Allan (National Australia Bank), Mike Andrea (Strategic Directions) and Bob Sharon (Green Global Consulting) discuss the impact of the NABERS data centre rating.
Judges notes: Fortescue Metals [The Benchmark Awards]
Judges notes: Fortescue Metals [The Benchmark Awards]
iTnews' panel of judges discuss Fortescue Metals 'New World of Work" project, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Retail [The Benchmark Awards]
Judges notes: Retail [The Benchmark Awards]
iTnews' panel of judges discuss the shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: Pacific Aluminium [The Benchmark Awards]
Judges notes: Pacific Aluminium [The Benchmark Awards]
iTnews' panel of judges discuss Pacific Aluminium's lightning fast service desk refresh, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Domino's Pizza [The Benchmark Awards]
Judges notes: Domino's Pizza [The Benchmark Awards]
iTnews' panel of judges discuss Domino's Pizza's shift to hosted services, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: McDonald's Australia [The Benchmark Awards]
Judges notes: McDonald's Australia [The Benchmark Awards]
iTnews' panel of judges discuss McDonald's Australia's new self-service portal for employees, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Latest Comments
Polls
Will you quit any cloud services in light of PRISM?

   |   View results
Yes
  68%
 
No
  32%
TOTAL VOTES: 53

Vote