back to article UK techies' union warns members after breach exposes sensitive personal details

UK trade union Prospect is notifying members of a breach that involved data such as sexual orientation and disabilities. According to disclosure emails seen by The Register sent to union members who work as scientists, engineers, techies, and managers, the attack took place in June, yet members were only notified this week. …

  1. m4r35n357 Silver badge

    Betrayed

    . . . by their "protectors".

    The internet keeps on giving! Between this and the OSA we (the UK) have everything neatly parcelled up ready for mass blackmail.

    1. Anonymous Coward
      Anonymous Coward

      Re: Betrayed

      It's worse then that. Prospect also manage MOD sites, including the Atomic Weapons Establishment.

      So yeah, they basically jeopardized national security.

      But here's 12 month Experian membership!

  2. Like a badger Silver badge

    What penalty can the ICO levy on a union?

    As a personal view, data breaches have been coming thick and fast, there's now zero excuse for the ICO not imposing major penalties, but in this case how can it? A fine just gets paid of of union funds, and and thus is paid directly by the members affected. The law allows for directors and officers to be held accountable, it's high time they were but I'm not holding my breath.

    ICO, Action Fraud, the police....all just administrators.

  3. Tron Silver badge

    They really don't need most of that info.

    You should store the minimum amount of information that you need. If you need one-off information for a survey, isolate it from the rest of your data and flush it when you have used it.

  4. FordPrefect

    Prospect are just about the most useless union you could be a member of. I was a member previously until I realised that every collective negotiation they had with my employer lead to a worse deal than the one originally proposed by the company. I've seen enough of their rep support to know I'd be better representing myself. I'd advise anyone who is currently a member has this union ever actually achieved anything worth the money you give them every month or are you giving them money for nothing ?

    1. elsergiovolador Silver badge

      Most unions are useless and they serve corporate interests rather than workers. Sad affair, really.

      1. Yet Another Anonymous coward Silver badge

        Join us in AUPSLOTP to fight AI answering the question.

        ( Amalgamated Union of Philosophers, Sages, Luminaries and Other Thinking Persons )

    2. Anonymous Coward
      Anonymous Coward

      They spend a lot of that money on taking legal action against a former member (£1.5 million) or on the GS girlfriend's IT project (£5 million+).

      The fact that this breach happened doesn't show good value for money...

  5. VoiceOfTruth Silver badge

    The same old crap every time there is a hack

    >> 12 months' worth of credit and identity monitoring to affected members through Experian.

    Experian seems to be monitoring half the country at this rate.

    There needs to be mandatory reporting within $shorttime to those affected. Three months down the line is useless.

    1. Furious Reg reader John

      Re: The same old crap every time there is a hack

      I wonder if Experian pay some commission to the hacking groups for each new bit of business they gain from the breaches?

      I also wonder if Experian charge newly breached organisations for the monitoring to be done on individuals who have already been involved in breaches where another organisation is already paying for monitoring?

      1. Yet Another Anonymous coward Silver badge

        Re: The same old crap every time there is a hack

        Or when it goes recursive

  6. Anonymous Coward
    Anonymous Coward

    Oh the irony ..

    Oh the irony .. no doubt it was some third-party contractor to blame.

    --

    Sexual orientation: Teletubby

    Faith: Pastafarian

    1. Yet Another Anonymous coward Silver badge

      Re: Oh the irony ..

      >Sexual orientation: Teletubby

      Which one ?

      And do you get your own flag ?

      1. Korev Silver badge
        Coat

        Re: Oh the irony ..

        There's no need to be Po faced

        1. Yet Another Anonymous coward Silver badge

          Re: Oh the irony ..

          Ooh - La La

  7. tiggity Silver badge

    "following other guidance provided by the National Cyber Security Centre (NCSC)"

    The total POS site that displays a blank page to a user with JavaScript disabled?

    A page that does not work with JavaScript disabled does not inspire me with any hope of trustworthy security advice.

    .. Yes, I could alter my "whitelists" (feel free to mentally replace that with whatever the PC term is), and see how good (or not) the content is, but I make a general rule of boycotting sites that fall at the first hurdle when I visit with my default of JS off.

  8. Anonymous Coward
    Anonymous Coward

    The union have shared the minimum amount of detail required of them

    Ironically, the email to affected members begins with the words ‘Private and confidential’ unlike my personal details that have been ‘impacted’.

    The complete lack of transparency about this matter is extraordinary! As an affected member the first I heard about this ‘IT security incident’ was on receiving an email yesterday that informed me that my details were ‘impacted’. This is because the union chose only to inform it’s members in June by posting on their website rather than emailing all members. An approach Mike Clancy stated was in the ‘interests of transparency’.

    At this point, it is completely unclear whether my data has been lost, inadvertently shared, or stolen by a group or individual? Only the union knows. They do state in their email that ‘those behind the incident’ have not yet made the data available online so it seems they do have some knowledge of who was responsible for the incident. They’re simply choosing not to divulge how the data was obtained which only suggests that poor security measures are to blame.

    I cannot have any faith in a union that has been so lacking in transparency to support me when the time is required. I will be cancelling my membership and moving to a different union.

  9. Anonymous Coward
    Anonymous Coward

    And the very next day...

    Prospect members get an email stating that the board has approved a 3% increase in union fees

    Satire is dead :0)

  10. The Union Codpiece

    It's the GS election next year and that the person responsible for this cock up is going to be standing again is beyond belief.

    That the NEC is supporting his re-election show their failure to govern properly. Instead of questioning management, they'd rather crawl up its arse.

    As for the presidential team, I've been stung by jellyfishes with more backbone than them.

    All of them should be turfed out.

  11. The Union Codpiece

    national security breach

    the union management, the presidential team and the nec are covering up one thing.

    this is a major national security breach.

    prospect represent a large number of members in the defence, telecommunication, police and energy sector.

    the data that has been leaked also included personal case files.

    that the data has not been found on any dark web forum is not a surprise. this breach could have been conducted by a group affiliated to a foreign state.

    and now staff involved in work on nuclear weapons development, nuclear submarines, maintenance of government communications and other areas have now been exposed.

    12 months of experian membership isn't going to cover this breach.

    a fish rots from the head down.

    they all need to go.

  12. Anonymous Coward
    Anonymous Coward

    There was a webinar earlier this week where the General Secretary tried (and failed in a lot of cases) to answer nearly 100 questions submitted by reps. Lots of evasion, lots of obfuscation. He looked like he is worried about his job, and so he should be. In a properly governed organisation he would fall on his sword. Very tellingly the most senior members of the union – the President, Vice President and Deputy Vice President were nowhere to be seen, and their absence wasn’t even mentioned let alone apologised for. A complete failure of leadership on their part – or perhaps they don’t want to be associated with a sinking ship. Either way Prospect/Bectu needs a complete overhaul in the way it is run.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like