Skip to content

Electoral Commission

Disclosed May 9, 20242 years agoConfirmed

Official notice

UK ICO reprimand for security failings

Reprimand issued to the Electoral Commission in respect of Articles 5(1)(f) and 32(1)(b). Between 24 August 2021 and 27 October 2022, a threat actor had access to the Electoral Commission’s systems and was able to access personal data held as part of the Electoral Register. This incident impacted approximately 40,000,000 individuals, and the initial access was gained via several unpatched software vulnerabilities. The investigation highlighted that appropriate technical and organisational measures were not in place at the time of the breach.

What is known

People affectedNot stated in the sources we have
DisclosedMay 9, 2024
AttackNot stated
Data exposedNot stated
SectorGovernment · GB
StatusConfirmed
Lawsuit or fineUK ICO reprimand (2024-05-09)

Sources

Source
UK ICO reprimand: The Electoral Commissionico.org.uk · Regulator

Notices filed

WhereFiledPeople
UK ICOregulator:GBMay 9, 2024
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (UK ICO), confirmed by UK ICO. Record counts are as reported. Not legal advice.

Everything about Electoral Commission

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.