Catastrophic MoD Data Breach Caused By Lack of Training On Excel (independent.co.uk) 53
A UK parliamentary inquiry found that a catastrophic Ministry of Defense breach exposing 18,700 Afghans could have been prevented with basic Excel training, after an employee unknowingly shared a hidden worksheet containing their details. The Independent reports: The leak, in February 2022, exposed the details of 18,700 Afghans who said they were in danger from the Taliban because of their links to UK forces and now wanted to escape to Britain. The blunder triggered an unprecedented superinjunction used against the national media, including The Independent, and prompted a secret evacuation program -- the cost of which is still unclear but which likely ran into the billions of pounds. Following the revelation by this outlet and others in July last year of the hidden operation, MPs set up an inquiry to scrutinize what had happened. In their report, the defense selection committee concluded that:
- The data breach could have been prevented if Ministry of Defense (MoD) personnel had received basic Excel training
- By August 2023, when the department discovered the leak, thousands of people already knew that a significant data incident had taken place
- The government did not strike "the right balance between operational secrecy and democratic accountability" -- and the superinjunction was in place for too long
- Secrecy denied affected Afghans the chance to take steps to protect themselves and their families and caused delays to evacuation program
- Thousands of Afghans eligible to come to Britain are still trapped in Afghanistan with the government failing to explain how they will help get families to safety.
MPs have called on the government to publish periodic reassessments of the risks facing Afghan applicants to UK resettlement schemes, with officials to report findings annually. They also want ministers to publish a clear policy explaining how they will help Afghans who are eligible to come to Britain but who have not yet been evacuated. The defense committee have also called on the MoD to explain who was responsible for data protection risk before the Afghan breach, criticizing the lack of accountability within the civil service.
- The data breach could have been prevented if Ministry of Defense (MoD) personnel had received basic Excel training
- By August 2023, when the department discovered the leak, thousands of people already knew that a significant data incident had taken place
- The government did not strike "the right balance between operational secrecy and democratic accountability" -- and the superinjunction was in place for too long
- Secrecy denied affected Afghans the chance to take steps to protect themselves and their families and caused delays to evacuation program
- Thousands of Afghans eligible to come to Britain are still trapped in Afghanistan with the government failing to explain how they will help get families to safety.
MPs have called on the government to publish periodic reassessments of the risks facing Afghan applicants to UK resettlement schemes, with officials to report findings annually. They also want ministers to publish a clear policy explaining how they will help Afghans who are eligible to come to Britain but who have not yet been evacuated. The defense committee have also called on the MoD to explain who was responsible for data protection risk before the Afghan breach, criticizing the lack of accountability within the civil service.
No it was not (Score:5, Insightful)
Sure, that's one way the breach might have been prevented, which is a much better word than "could" here because the worker would still have had to first know look for a hidden tab, and then actually do it. People forget to do things they know how to do all the time.
A better way would be to prevent sending any consequential attachments (bigger than a signature image - or even block those too, as sig images can be sourced from the web) and use a sharing portal which prevents embarrassing accidents like this by stripping out any questionable content and being extremely strict about it.
If you're depending on a single worker to remember and do something to avoid people losing their lives, you have already created a bad process, and people will die for it sooner or later.
Re: (Score:2)
Re: (Score:3)
And it works badly. I have personally recovered data were the document was "reviewed". They just were smart enough to ask an actual expert in addition.
Re: (Score:1)
Re: No it was not (Score:2)
Re: (Score:1)
And how many times have "redacted" pdf files been found to have simple black bars draw over text that still exists in the pdf file.
Re: No it was not (Score:2)
That's what I was talking about in another thread in this discussion when I said PDFs have their own issues but they wouldn't apply here. That's a problem when redacting PDFs, WHICH NO ONE SHOULD EVER DO. They should either go back to the source document, redact that, and create a new PDF; Or they should create an image from the PDF, redact that, and then they can publish that as a new PDF.
Re: (Score:1)
Actually, it's exactly the same issue. Just using a different program.
The pdf redaction folks drew black bars over extant text and hid it that way.
The excel chap clicked on "hide this tab".
So both of them used what they assumed was a method to hide the data. It turned out to be nothing of the kind, of course, but in both of these situations they made exactly the same mistake using exactly the same set of expectations and ended up with the same results.
Re: (Score:2)
Actually, it's exactly the same issue. Just using a different program.
It's not the same issue.
The pdf redaction folks drew black bars over extant text and hid it that way.
The excel chap clicked on "hide this tab".
There is no evidence that anyone was trying to redact anything when they hid the tab, they may have just been trying not to confuse the recipient. The person who hid the sheet is not the person who shared the document. Any similarity which did exist would be irrelevant because format shifting to a PDF would still solve this problem.
Really? (Score:5, Insightful)
I doubt that any amount of Excel training would have helped for this specific issue. That mistake could be made by anyone. Once you hide a worksheet it's not obvious it's still attached to your workbook... because it's hidden. It's a mistake waiting to happen.
Re: (Score:3)
It's an insane thing to do with sensitive data. It's a great thing to do with tables the users don't need to access when you're using Excel for something that really should be done with a database application :)
Re: Really? (Score:5, Insightful)
What's insane is that they had a committee investigate the incident and the best they could come up with in their root cause analysis is that the end user needed more excel training.
Re: (Score:2)
It's crazy-making but not completely crazy since their goal was to scapegoat.
It's still a little crazy, because whose fault is it the user wasn't trained?
Re: (Score:2)
Re: (Score:2)
The problem is that Excel is entirely the wrong tool for something like that. Using it this way is basically gross negligence.
Re: (Score:2)
I doubt that any amount of Excel training would have helped for this specific issue. That mistake could be made by anyone. Once you hide a worksheet it's not obvious it's still attached to your workbook... because it's hidden. It's a mistake waiting to happen.
Maybe someone should make a course and include that so people don't make that mistake.
Re: (Score:2)
Also, who wants to spin up a secure database, and reporting interface, for a one-off contact list? Apparently, a lot of commenters would do...
Why did you use Excel? (Score:5, Interesting)
Re: (Score:3)
Name an alternative to a spreadsheet that's simple to use and doesn't require an overworked and usually unenthusiastic IT department to set up?
The issue here isn't that they used a spreadsheet, it's that spreadsheets are still treated as toys despite being the exact opposite.
Re: (Score:2)
Name an alternative to a spreadsheet that's simple to use and doesn't require an overworked and usually unenthusiastic IT department to set up?
A typical "modern" (as in, recently developed, the only meaning of the word which usually applies to government IT) solution is to pay a contractor way too much to develop a solution. Your IT department is barely involved.
Government software is seemingly always super duper specific to the task at hand with no thought for the future, so then you get to pay more millions (or billions) for a new system or major revisions to the old one in a few years. But at least it doesn't generally have this kind of problem
Re: (Score:2)
Re: (Score:2)
All you really need is a server, locked down like a nuns nasty, Postgres (or another DB, MySQL, MariaDB, MongoDB, etc...), and a frontend that has limited scoped access.
Yeah, but there's usually some troll squatting atop the problem preventing it from being resolved.
Re: (Score:2)
Re: (Score:2)
Re: Why did you use Excel? (Score:1)
Re: (Score:2)
Re: (Score:2)
Why do people grossly misuse spreadsheets?
Because they're the most powerful and easy to use, and likely only, data manipulation tool a person with no hint of computing-specific education is likely to run across.
Re: (Score:2)
Re: (Score:3)
Re: (Score:2)
It's also pointing out that a spreadsheet is not a data management system, which everyone should understand. There's a reason we have databases, and everyone has heard of them, regardless if you know how to use them.
Re: (Score:2)
Note this is also why people use Python. Python isn't the best language, Ruby is.
Re: (Score:2)
Re: (Score:2)
Because the highly educated dumb-asses only learned spreadsheets in College. And like most places with a rigid hierarchy would not have dreamed of asking their own IT people for a more secure solution. There are the same people who were using WhatsApp, fax machines and handwritten notes through out the Covid pandemic.
Re: (Score:2)
MoD should ... (Score:2)
Re: (Score:2)
But they are the side with the battleships. :-)
Pointless (Score:2)
Considering Excel encryption/protection has been broken on every version of Excel from day 1, if that is what they are relying on, I think their security consultants may need some training.
Gonna Need Some Proof Chief (Score:2)
Excel's file encryption mechanisms are extremely secure. It relied on 128AES encryption until version 2016 when 256AES became available. Excel encryption is susceptible only to brute force password spraying attacks facilitated by weak passwords.
If you can prove otherwise, we'd love to see it.
P.S. This post refers to encryption not cell/sheet protection.
Or maybe intentional? (Score:2)
Excel sheet for sensitive data?
Re: (Score:2)
Excel sheet for sensitive data?
I've (apparently) got news for you, governments use excel spreadsheets for sensitive data constantly. For a lot of purposes it is the right tool for the job... doesn't sound like it was this time, to be fair, but that doesn't change the general statement. Spreadsheets are often a great place to do data munging before giving the data a final home. The spreadsheets are not the problem, a policy of sharing spreadsheets without having them verified safe to share is. It's a much better policy for example to prin
Re: Or maybe intentional? (Score:2)
A spreadsheet is as good as the software who handles it.
And Excel doesn't seem to ... excell in security and safety.
Nope! (Score:2)
The issue is that the current Sharepoint/OneDrive/Teams sharing feature is an absolute shit show of unmanageability.
We're getting more an more of these unintentional shares and rather than clamping down on the data, people are just getting acclimatize and accepting it as if there is nothing that can be done about it.
There's always been a trade off between usability/convenience and security. We're currently so far into convenience that security is not even an after thought.
Microsoft ends the universe (Score:3)
Microsoft has made is so that everyone who is not a programmer or database engineer defaults to Excel for creating databases. Then they share those databases by emailing them to people. This is the dumbest way to maintain a database. It's also the least secure.
There are many ways to store and share columnar data and any of them is better than Excel. Governments use Excel for everything, so do businesses. Excel is hot, stinking garbage as is most Microsoft software. Same goes for Oracle. Nobody here needs to be told this though; it's common knowledge among those who have even the most modest technical aptitude.
Re: Microsoft ends the universe (Score:2)
Re: (Score:2)
Something stops being a database when you make a copy of it and send it to someone else. It's now a document IMO.
If you are migrating or copying a database, then that's a different use-case. It sounds like someone was trying to provide some information, and didn't know due to a stupid feature of Excel that they were sending a lot more than they intended.
If you require strong authentication to access a database through some kind of portal etc, the data can be secured. Once it's out there in someone's inbox,
The error was using a Microsoft product! (Score:2)
When will people understand this is insecure. And a very non professional, clueless way to share information.
But then why would they understand that, they are using Microsoft products in the real world.
Nothing New here.. move along.. (Score:2)
the UK government has a strong history of ballsing up anything to do with Excel.
Here is actual behind the scenes footage of the conversation as the horror unfolded : https://www.youtube.com/watch?... [youtube.com]
Why Britain? (Score:2)
Everything old .... (Score:2)
Probably still happening, but I remember when the first few Word docs were sent out with the full "edit / change history" contained within.
Almost as dumb -- on Microsoft's part, as allowing you to embed , say an Excel workbook inside a Word doc. Practicallly nobody understood that the entire workbook was there not just the weenie little table being displayed.