Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Comment: Home Office Offers An Apology For Wrongly Sharing 500 Email Addresses Of Windrush Victims
News & Analysis

Comment: Home Office Offers An Apology For Wrongly Sharing 500 Email Addresses Of Windrush Victims

ISBuzz TeamBy ISBuzz TeamApril 9, 20193 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Home Office has apologised to the Windrush generation again after admitting it wrongly shared 500 private email addresses while launching the compensation scheme. In what is being described as an “administrative error” by Immigration Minister Caroline Nokes has led to a breach of data protection rules. An internal review has been launched and the matter has been referred to the Information Commissioner. 

Twitter Reaction: 

Oooh – Could this be subject to the first #GDPR fine issued by @ICOnews? > BBC News – #Windrush: Home Office admits data breach in compensation scheme https://t.co/JKUTjuaVpJ

— Ibrahim Hasan (@IbrahimH_Lawyer) April 9, 2019

And the beat goes on and on as the agony of the Windrush #hostileenvironment is prolonged. First the Home Office couldn't find data on Windrushers and now they are giving it away freely!!

Windrush: Home Office admits data breach in compensation scheme https://t.co/gTCwMUVQwF

— Callton Young (@CalltonYoung) April 8, 2019

Government announce plans for "duty of care" online safety laws https://t.co/gSH9FbRkFB
Home Office admits to Windrush compensation data breach https://t.co/WqCV4KKboJ

— Mr Ethical (@nw_nicholas) April 8, 2019

Experts Comments:  

Jonathan Deveaux, Head of Enterprise Data Protection at comforte AG: 

“Even though there are technologies available in the Cybersecurity market for masking or anonymising email addresses, this breach was mainly due to a poor, human based-decision. More organizations need to enable data protection of personal or sensitive info to ‘automatically’ occur, upon creation of the data, so that ‘accidental insider’ events like this happen less often.  The data-centric security model adheres to this and is starting to gain momentum with organizations who want to stay out of the news headlines and restore data privacy.”  

Tony Pepper, CEO at Egress Software:

Tony Pepper“Immigration minister, Caroline Nokes, has again apologised to the Windrush generation after about 500 private email addresses were mistakenly shared with recipients of a mailing list for the compensation scheme. When this accidental incident occurred, there was no safety net and no way of alerting the sender of the mistake. This is a common error that we’ve also seen in our recent research, where 45% of employees who accidentally shared information sent it to the wrong person. 

Traditional solutions to prevent inbound and outbound data breaches – such as firewalls, endpoint security, encryption and malware scanning – have little to no impact on accidental incidents, as they can’t stop someone from doing something like sending an email to multiple recipients using To/Cc instead of Bcc. This is because they can’t tell the difference between ‘good’ and ‘bad’ user behaviour (whether accidental or malicious). 

While organisations typically prioritise the malicious outsider over the accidental insider threat, the latter has been fundamentally underestimated. With intelligently applied machine learning and big data analysis combined with a people-centric  approach to technology and awareness programmes, it is possible to mitigate against such human errors and enhance organisations’ cybersecurity.”  

Tim Sadler, CEO at Tessian:

“Everyone knows that sinking feeling when an email is sent to the wrong person. But in this case, a simple ‘administrative error’ has meant highly sensitive information has landed in the wrong hands and put personal data at risk.  

“Misdirected emails are consistently one of the main forms of data security incident reported to the ICO. This incident highlights the importance of cybersecurity and data protection policies that focus on protecting people in order to prevent breaches caused by human error, if not only to protect the sensitive data organisations hold but also to prevent the headlines that cause reputational damage.” 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The next phase of endpoint security starts with simplicity

June 24, 20266 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}