Story image

Tasmanian elector data breached via forms on Electoral Commission site

03 Jul 18

Last week, the Tasmanian Electoral Commission was informed by Barcelona-based company Typeform that an unknown third party had gained access to one of their servers and downloaded certain information. 

Typeform online forms have been used on the TEC website since 2015 for some of its election services.

The breach involved an unknown attacker downloading a backup file. 

The breach was identified by the company on June 27, 2018, with the vulnerability closed down within half an hour of detection.  

Typeform’s full investigation of the breach identified that data collected through 5 forms on the TEC website had been stolen. 

Whilst some of the stolen elector data captured in some of these forms has already been made public, such as candidate statements for a local government by-election, it is believed that the breach also captured name, address, email and date of birth information provided by electors when applying for an express vote at the recent State and Legislative Council elections.

The Electoral Commission will be contacting electors that used these services in the coming days to inform them of the breach.

The Electoral Commission apologised for the breach and promised to re-evaluate its collection procedures and internal security elements around its storage of electoral information for future events.

The breach has no connection to the national or state electoral roll.

Two weeks ago, a breach of online recruitment services organisation PageUp left personal data from the staff at the Australia Attorney-General’s Office exposed.

Malware was found on the company systems used to store private data, including banking details and personally identifying details.

Other employers that were using PageUp’s human resources software included Telstra, Medibank, Australia Post, and more. 

In a statement, PageUp says that while sensitive data was accessed, it “has advised that no employment contracts, applicant resumes, Australian tax file numbers, credit card information or bank account information were affected.”

“In other words, no Australian information may actually have been stolen.”

McAfee named Leader in Magic Quadrant an eighth time
The company has been once again named as a Leader in the Gartner Magic Quadrant for Security Information and Event Management.
Symantec and Fortinet partner for integration
The partnership will deliver essential security controls across endpoint, network, and cloud environments.
Is Supermicro innocent? 3rd party test finds no malicious hardware
One of the larger scandals within IT circles took place this year with Bloomberg firing shots at Supermicro - now Supermicro is firing back.
25% of malicious emails still make it through to recipients
Popular email security programmes may fail to detect as much as 25% of all emails with malicious or dangerous attachments, a study from Mimecast says.
Google Cloud, Palo Alto Networks extend partnership
Google Cloud and Palo Alto Networks have extended their partnership to include more security features and customer support for all major public clouds.
Using blockchain to ensure regulatory compliance
“Data privacy regulations such as the GDPR require you to put better safeguards in place to protect customer data, and to prove you’ve done it."
A10 aims to secure Kubernetes container environments
The solution aims to provide teams deploying microservices applications with an automated way to integrate enterprise-grade security with comprehensive application visibility and analytics.
DigiCert conquers Google's distrust of Symantec certs
“This could have been an extremely disruptive event to online commerce," comments DigiCert CEO John Merrill.