iTnews

Hackers hack British police database, publish logins

By Dan Raywood on Sep 4, 2012 9:53AM
Hackers hack British police database, publish logins

Dozens of officers affected.

Hackers have raided the website of a British Police unit and published login details and passwords belonging to dozens of officers.

According to BBC News, Hertfordshire Police confirmed that information stored on an externally hosted database was published online and that the data, including phone numbers and IP addresses, relates to a number of officers in Britian's Safer Neighbourhood teams.

A statement said that it was investigating the incident and as a precaution, the pages had been temporarily disabled while the incident was investigated.

“There is absolutely no suggestion that any personal data relating to officers or members of the public has been, or could have been compromise," it said.

"Nevertheless matters of IT security are extremely important to the Constabulary and an investigation is already under way."

The hacker added an ‘OpFreeAssange' banner to the details posted online, however, the hacker wrote that they were not affiliated with the Anonymous hacking collective.

Bitdefender chief security researcher Catalin Cosoi said the exposed list of employee names and corresponding IPs could be used in cyber crime operations that required identification of a specific machine.

NCC Group technical director Paul Vlissidis said externally hosted databases could be a "nasty potential security flaw".

“Miscreants are certainly very wise to this. We need to move towards a culture where it's common policy to audit external suppliers and make sure their security is up to scratch.”

Stonesoft UK and Ireland country manager Ash Patel said the hack raises questions about other potential damage including the introduction of malware and the risk that other data may have been stolen.

“Public sector organisations need to understand that, by hosting sites with third parties or outsourcing such important services to system integrators, does not take responsibility away from those who are employed to ensure the security of ‘our' data. It is time that it was made clear that the responsibility lies with the government and its employees in the same way that the nation's security lies with the armed forces.

“It is also important to note that Hertfordshire Police's website was externally hosted and this, as always, highlights that when employing this parties to host sites, the first and most important question that should be asked is with regards to security, after which can come questions around cost and availability. This is even more so the case when the organisations are of public interest.”

This article originally appeared at scmagazineuk.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, UK edition
Tags:
bitdefe65279nderdata breachhackingncc grouppolicesecurity

Partner Content

DoT Victoria turns to Oracle to implement unified cloud-based platform
Promoted Content DoT Victoria turns to Oracle to implement unified cloud-based platform
Vast majority of surveyed firms still rely on password authentication
Promoted Content Vast majority of surveyed firms still rely on password authentication
Top 5 Benefits of Managed IT Services
Promoted Content Top 5 Benefits of Managed IT Services
Alienated from your own data? You’re not alone
Promoted Content Alienated from your own data? You’re not alone

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • 11th Annual Fraud Prevention Summit 2022
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Dan Raywood
Sep 4 2012
9:53AM
0 Comments

Related Articles

  • Australian gov data breach numbers slip out of public view
  • BLE ‘relay attack’ bad news for Tesla, digital locks
  • Victorians lost $31.9 million to business email compromise in 2021
  • Lapsus$ hackers exploited Okta supplier's security lapses
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Kmart Australia stands up consent-as-a-service platform

Kmart Australia stands up consent-as-a-service platform

Telstra to open its 5G network to wholesale customers

Telstra to open its 5G network to wholesale customers

Active Directory defaults lead to no-fix PrivEsc vulnerability

Active Directory defaults lead to no-fix PrivEsc vulnerability

Westpac promotes its head of technology to mortgage role

Westpac promotes its head of technology to mortgage role

Digital Nation

As NFTs gain traction, businesses start taking early bets
As NFTs gain traction, businesses start taking early bets
COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
The other ‘CTO’: The emerging role of the chief transformation officer
The other ‘CTO’: The emerging role of the chief transformation officer
Metaverse hype will transition into new business models by mid decade: Gartner
Metaverse hype will transition into new business models by mid decade: Gartner
Case Study: PlayHQ leverages graph technologies for sports administration
Case Study: PlayHQ leverages graph technologies for sports administration
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.