Electoral Commission hack: Five things you need to know

The public statement only raises more questions

Tom Allen
clock • 5 min read
Electoral Commission hack: Five things you need to know

Yesterday the UK's election regulator, the Electoral Commission, announced that it was hacked in 2021. The breach took more than a year to find, and 10 more months for the public to be told. Here are the five key takeaways you need to know.

1. Who's responsible?

So far, we don't know. Attribution is notoriously difficult in cybercrime, and all the Commission says is that "hostile actors" accessed its systems in August 2021.

The length of time between the breach taking place and being discovered will have made attribution a bit more difficult. That said, the "external security experts" the Commission is working with should still be able to make some educated guesses, using information like attack paths, payloads and motives - especially considering how long they've had to analyse the incident.

The fact that the attackers remain unidentified is a concern. Interference in democratic systems by hostile states carries significant implications, and there is a strong argument for this being discussed openly and transparently.

We also don't know how the attackers got in. Commission Chair John Pullinger told the BBC that the "very sophisticated" attack involved using "software to try and get in and evade our systems," but this leaves many unanswered questions.

You may also like
Hackers launch brute-force attacks on business VPNs and more

Threats and Risks

The attacks rely on trial-and-error attempts to crack login credentials

clock 18 April 2024 • 2 min read
Last chance to register for Cybersecurity Festival 2024

Security

Book your free place today

clock 18 April 2024 • 2 min read
Interview: Illumio, Security Excellence Awards finalist

Security

'We are one team, delivering one platform, on one mission to ensure that organisations can realise a future without any high-profile breaches'

clock 17 April 2024 • 5 min read

Sign up to our newsletter

The best news, stories, features and photos from the day in one perfectly formed email.

More on Hacking

Global government networks breached in 'ArcaneDoor' espionage campaign

Global government networks breached in 'ArcaneDoor' espionage campaign

Threat actors compromised networks using Cisco zero-day exploits

clock 26 April 2024 • 2 min read
Millions at risk as hackers threaten World-Check database leak

Millions at risk as hackers threaten World-Check database leak

Company says compromised data originated from a third-party vendor

clock 22 April 2024 • 2 min read
Roku reports cyber breach impacting 576,000 accounts

Roku reports cyber breach impacting 576,000 accounts

Compromised data was used to make unauthorised purchases in fewer than 400 cases

clock 15 April 2024 • 2 min read