Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

Mumsnet Data Breach - Q&A

189 replies

JustineMumsnet · 19/04/2018 21:04

As many of you already know, some screenshots of Mumsnet posts were recently uploaded to Twitter by a former Mumsnet intern – here’s a link to a previous thread discussing this in case you've not seen it.

Three of the screenshots showed an Admin’s view of the site and therefore contained the IP addresses of the posters concerned.

Understandably there have been loads of questions about the implications, about what data we hold and who has access to it so we've collated them here. Please do post any queries here or email [email protected] if you’ve any concerns or further questions.

Thanks and huge apologies if this has caused you any concern.

OP posts:
Waspnest · 21/04/2018 18:05

Kreigers, I agree with everything you've said. MN only found out about the breach because of one diligent MNer. The stolen info could be out there on Reddit, Tumblr or a memory stick that EH's given to a friend. I have no idea why MN even contacted EH when they found out about the breach. They should have immediately turned over everything they knew to the police and ICO and let them deal with it. Some misplaced loyalty seemed to stop them from doing that. If EH has committed a crime then by allowing/encouraging her to delete any further evidence I'd say they're becoming dangerously close to being an accessory. I think they need to employ both new techie people and new lawyers.

Such a shame because I love the community here but this minimising will destroy trust in the site. (Mind you most of the users are probably completely unaware of what's happened - I have no idea why they haven't been told.)

CrochetBelle · 21/04/2018 17:25

Have MNHQ answered to anyone yet as to how long they keep a postal address on file?

KreigersClones · 21/04/2018 15:40

Oh, wow, I didn’t realise the post was so long Blush

KreigersClones · 21/04/2018 15:40

The actual data breach, in and of itself, well I mean, it’s not great, but it happens.
However I think it has been handled so,so, so badly.
The apparent minimising, the apparent reluctance to report, the ‘a bit cross’ comment, the ‘I don’t think’ she has, ‘I don’t believe she has’ comments, when there’s NO way of actually knowing, referring to her contract of employment as if that were the issue rather than the actual law.
However, for me the worst part of it is learning that you’ve basically ‘made her promise’ to delete anything mn related she finds on her devices. I find Justine openly saying that astonishing. As a pp has said, it’s literally reporting someone to the police (whether that be as a ‘curtesy’,or otherwise) and then colluding with them to destroy any evidence. Then saying ‘I don’t know why people think we appear to minimising this/covering it up’. It’s madness.
I’m also extremely concerned that mn think that whatever we post is not sensitive personal information, when every member of staff seems to have our IP address, a complete history of our email addresses, actual home addresses, a complete history of private messages including deleted ones. etc etc.
We know that someone in the company will be able to access this data, but not that any and all could, including staff on flipping work experience.
I know that they’ve obviously had legal advice telling them to change this, and they HAVE reported now, but the fact is, it was initially said that basically ‘we’re dealing with this, we don’t see the need to report it at this stage as we’ve spoke to Emma and we believe it was a big mistake, and she’s assured us there’s nothing else, and said sorry to us’.
As I said before, been handled so, so badly.

MagneticMan · 21/04/2018 14:21

So if someone has, for instance, applied to review a book or product how long do you keep their address for?

Longer than 21 days I'll bet.

CotswoldStrife · 21/04/2018 14:14

You've handled this so badly, MNHQ, and that's what bothers people.

We are looking for robust action not a promise and a deletion of evidence. Perhaps it is just those of us who have dealings with data that realise the seriousness of the breach but the fact that this thread isn't trending and that you haven't emailed your users to let them know is hard to forgive. If you'd handled it better in the first place, users would be more reassured.

So if someone has, for instance, applied to review a book or product how long do you keep their address for?

MipMipMip · 21/04/2018 14:09

I hope hiring processes will include Google searches and looking at social media (including who they follow) from now on. I suspect moles will be wise to this though and make sure there's nothing interesting before applying.

Tartanscarf · 21/04/2018 13:58

This reply has been deleted

Message withdrawn at poster's request.

MagneticMan · 21/04/2018 13:48

Were you using G suite? If so you have a limited time to restore the deleted data.

support.google.com/a/answer/6052340?hl=en

Have you employed a forensic IT expert yet MNHQ?

Why are you allowing data to be destroyed in a potential criminal case?

Tartanscarf · 21/04/2018 13:32

This reply has been deleted

Message withdrawn at poster's request.

Tartanscarf · 21/04/2018 13:31

This reply has been deleted

Message withdrawn at poster's request.

MagneticMan · 21/04/2018 13:25

"Not all of our systems currently allow a complete data audit; we’re reviewing that in the light of this incident but we can find no evidence of a further data breach. All our emails and files are handled through Google Business Apps. When a staff member leaves, we suspend their account as part of the exit process. The account remains suspended for 20 days, after which Google deletes the data (as has happened in this case). We’ve passed this information on to the police, who will decide on further action regarding the intern’s personal devices."

You appear to be saying that you have no way of knowing exactly what information EH accessed as it has now been deleted?

Well that's reassuring Hmm

BoreOfWhabylon · 21/04/2018 11:35

Thank you KateMumsnet

And thanks also @JessicaJonesJacket for your very helpful and informative posts.

ItsAllGoingToBeFine · 21/04/2018 11:19

Just to let you know that we've added to the Data Breach Q&A page over here to answer some more questions

That is much improved. Thank you :)

noblegiraffe · 21/04/2018 11:03

“We’re now going to change our processes and will no longer retain any but the current email address.”

Thanks for this, MNHQ!

KateMumsnet · 21/04/2018 10:48

Hi all

Just to let you know that we've added to the Data Breach Q&A page over here to answer some more questions.

KateMumsnet · 21/04/2018 10:44

@Tartanscarf

You also have pre ticked boxes for emails to be sent is that due to change prior to GDPR?

Yes @Tartanscarf - pre-ticked boxes for email or data content will be left open from next month, in line with GDPR.

Tartanscarf · 21/04/2018 09:53

This reply has been deleted

Message withdrawn at poster's request.

JessicaJonesJacket · 21/04/2018 09:20

I'm not sure that they never planned to report it. I think Justine made her initial responses so there was a presence on the boards but, rightly, she didn't decide or announce which may be two different things their response until she had taken advice from (I'm guessing) their IT, legal and DPA teams, as well as the police.
As for a mass email, I would want MNHQ to be sure of the security of their system and tbh, their staff, before sending a mass email which handily collates all users' details into the one email list (or multiple email lists).
I'm not trying to reassure you MipMip. This has shown up massive failings. But it's rare for a company in crisis mode to be expected to be as transparent as we're demanding. And I'm very conscious of the gfs, trolls and saboteurs currently posting all over MN who would love a blueprint of their future security precautions.

MipMipMip · 21/04/2018 08:47

They could send out two emails, the first saying "We have had a breach, we don't think it's serious but we have launched a full investigation and security review" instead of just trying to pretend it hasn't happen.

I'm cross about what happen. It's bad, it shouldn't have been possible but as people have said it is very hard to do anything against a determined individual. I am furious about Mumsnet's response. They are minimising it, they are not admitting they have no idea of the size, they didn't plan to report it until pressured to, they are taking the word of the person responsible that there is nothing worse. They appear to have no idea of how serious this potentially is and don't appear to be listening to people telling them. They also have no idea of the type of data they hold. I'm struggling to forgive this.

AngryAttackKittens · 21/04/2018 07:38

That sounded harsh. I'm not suggesting that the people here saying their company allows that are idiots. Whoever set things up that way otoh...

AngryAttackKittens · 21/04/2018 07:21

Yeah the people going "oh my company does things like that too" are making me wonder if I've just really lucked out in terms of working for companies not run by idiots.

JessicaJonesJacket · 21/04/2018 07:07

Angry Yy but being cautious and being incompetent are going to look the same at this stage unless they put out a holding statement that says 'we can't provide any more detail until we, the IOC and the police have completed our investigation'. But that's a response that could also badly impact faith in the site. In an ideal world, they'd release a statement from an independent IT/DPA company saying they're responsible for creating a robust system (processes and IT) going forward. But, in the current climate they have to make sure any external consultancy isn't compromised.
I agree with your point about, what seems to have been, universal access to the user database rather than it being staggered on a 'need to know for your role basis'. But there have been posters on other threads saying they have similar access in other organisations when they are in PR/comms' roles which tbh I find staggering. Segmenting access and protecting data have been fundamental principles everywhere I have worked.

AngryAttackKittens · 21/04/2018 06:54

Oh absolutely, there are reasons not to tell us what they're doing to update their systems and protocols. It's the fact that they don't seem to think they need to do so that's worrying people.

JessicaJonesJacket · 21/04/2018 06:51

I think we have to bear in mind that MNHQ is responding to three problems. One is a person acting in bad faith. The other is how MNHQ manages their staff, systems and processes.The third is how they manage user concerns.

There's a tension between them which impacts on what can be posted here.

Telling the general public (which is what happens when they post here) your recovery and security plans would benefit saboteurs. Sending an user-wide email when you're unsure how much your system and security have been compromised could be unwise until the investigations have been completed.

I appreciate why people are concerned and want answered but MNHQ have to address and balance all three issues in a way that enables them and IOC and the police to complete their investigation and that will provide most security going forward.