Electoral Commission
Disclosed May 9, 20242 years agoConfirmed
UK ICO reprimand for security failings
Reprimand issued to the Electoral Commission in respect of Articles 5(1)(f) and 32(1)(b). Between 24 August 2021 and 27 October 2022, a threat actor had access to the Electoral Commission’s systems and was able to access personal data held as part of the Electoral Register. This incident impacted approximately 40,000,000 individuals, and the initial access was gained via several unpatched software vulnerabilities. The investigation highlighted that appropriate technical and organisational measures were not in place at the time of the breach.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | May 9, 2024 |
| Attack | Not stated |
| Data exposed | Not stated |
| Sector | Government · GB |
| Status | Confirmed |
| Lawsuit or fine | UK ICO reprimand (2024-05-09) |
Sources
| Source | |
|---|---|
| UK ICO reprimand: The Electoral Commissionico.org.uk · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| UK ICOregulator:GB | May 9, 2024 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (UK ICO), confirmed by UK ICO. Record counts are as reported. Not legal advice.