Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

Mumsnet data breach - please read

868 replies

JustineMumsnet · 07/02/2019 12:40

As some of you know, we're very sorry to say that we’ve become aware of a data breach which affected some Mumsnet user accounts

What happened?
There was a problem affecting Mumsnet user logins between 2pm of Tuesday 5 February and 9am on Thursday 7 February 2019. During this time, it appears that a user logging into their account at the same time as another user logged in, could have had their account info switched.

Why has this happened?
We believe that a software change, as part of moving our services to the cloud, that was put in place on Tuesday pm was the cause of this issue. We reversed that change this morning. Since then there have been no further incidents.

How did Mumsnet find out this was happening?
Late last night, a Mumsnet user alerted us to the fact that they were able to log in to and view the details of another user’s account.

What information could have been affected?
If someone other than you logs into your account, they can see:
your email address
your account details
your posting history
your personal messages

They would NOT have been able to see your password because that data is encrypted and they would not have been able to change your password because you need to input a password to do that.

How many people are affected?
At the moment, we don’t know for sure but we are investigating the logs and hope to know definitively very soon. We do know that approximately 4000 user accounts were logged into in the period in question but we don’t as yet know which of those were actually breached (ie also affected by a mismatched login), although we know for sure it wasn’t every account. We have been made aware by users of 14 incidents when this occurred and have contacted the individuals that we know were affected. We are working hard to establish if there were more.

What have you done about it so far?
We’ve reversed the software change that was made on Tuesday pm, and this morning we forced a log out, requiring users to log in again before they can post. This ensures that anyone who had inadvertently logged in as someone else will no longer be logged in to the wrong account.

Where can I get updates?
We’re posting about the situation on this thread, and will update as and when we have further relevant info.

What happens next?
When we have any further substantial information affecting the security of Mumsnet user accounts we will send another email and post on the site.

We’re very sorry.
You’ve every right to expect your Mumsnet account to be secure and private. We are working urgently to discover exactly how this breach happened and to learn and improve our processes. We will also keep you informed about what is happening. We know some of you will be very worried by the possibility that your account has been breached - please mail us on [email protected] if you’d like to discuss your individual account details. We will of course be reporting this incident to the Information Commissioner.

Thanks to all who brought this to our attention.

Justine

OP posts:
Thread gallery
5
madvixen · 08/02/2019 10:53

@GerryblewuptheER I've had 8 cold calls since yesterday morning but also haven't received an email stating that my account was one of the ones affected

RedToothBrush · 08/02/2019 10:53

Imagine a bank said this if there was a security breach with their own systems

a) The initial source of the breech was stopped
b) Are you really comparing a bank with thousands of paid employees and contractors to MN who will have a small IT team and will probably have to get in security specialists for this crisis because they don't have them contracted to them on a day to day basis?

If you are then I'm afraid you really do not understand the situation.

Banks have more security issues than you realise. They are just better at a) responding to them because they have dedicated teams for it b) have multiple highly skilled people on call able to do something about it faster.

Honestly it's like comparing apples and pears. People do need to realise what a company the size of MN has immediate physical ability to deal with. Yes they make a lot of money and yes they need to employ some one who does have this knowledge but I don't think it viable to have whole teams on standby because they be sat there twiddling their thumbs 99% of the time.

It's something MN probably needs to outsource for, and that comes with it's own complications.

Good security specialists are hard enough to find as it is. Too few and too much demand. Plus there has been an increasing skill set shortage since 2016.

Plus many IT specialists blag and exaggerate their ability and if you aren't knowledgeable yourself when you hire someone, it's easy to not realise the knowledge limitations of that hire. Smaller companies have a distinct disadvantage here because they don't have staff at the interview stage to be able to test the range of knowledge until you have a major incident.

MN have my sympathy on this level and I understand the limitations they have compared to a bank or other social media companies.

It still should not have happened and it still should have been handled far better and its no less serious, but I'm realistic and pragmatic about it too.

C8H10N4O2 · 08/02/2019 10:52

@PetuliaBlavatsky

Glad to hear they have been in touch, hopefully they have also contacted the other reporters and will publish something about it quickly so that all iCloud keychain users can check their situation. Even if its just a warning being published.

C8H10N4O2 · 08/02/2019 10:51

Even IT people need to sleep and if they have been working flat out since the breech it's a ridiculous thing to suggest they should work over a 24 hr shift!!!

Which no one suggested.

What there should be is someone who can respond to questions with stock information, rather than unpaid volunteers.

The people investigating the problem and trying to fix it are not going to be the same people who are managing comms (or shouldn't be).

That said I have absolutely done 24,36,48 hr shifts and longer in a crisis, most IT people will have done at some point (note I'm not suggesting this should be done here, just that it isn't quite the bizarre notion implied). 24*7 support for a commercial site which contains large amounts of data in this class should be in place.

This is basic breach protocol, not rocket science, especially for a site which hold a significant amount of both personal and sensitive data.

There have been numerous additional questions and concerns raised during this period as people access the site at different times of day. Many of the questions have been triggered by unclear answers earlier in the process - again weak breach protocol. The requirement for a clear and tested breach protocol is there to cover exactly this situation.

NellMumsnet · 08/02/2019 10:48

Hello, we are compiling FAQs that we're hoping will address many of your questions. We're sorry that this is taking some time -- we want to be 100% sure on each answer.
We'll post those asap on here and on a separate page so that they can easily be found and linked to.
We're also going through this thread to tackle individual account questions and are mostly contacting you directly rather than replying on the thread. But we will add any answers that would be useful to other people to the FAQs.
Thank you so much for all the comments and details.

Frainbreeze · 08/02/2019 10:45

Sorry for reposting, but I wanted to tag MNHQ/Justine in this. @JustineMumsnet @MNHQ

Although the biggest issue on MN technologically is piling new shite and updates onto a framework that is slow, buggy, and outdated. MN would be best-served by building from the ground up. Sooner or later there will be issues with the current methodology. Nothing to do with site design either.

Why don't you re-build rather than the current approach which isn't working, and clearly causing problems, the latest engineered in this thread?

IT people have likely been working on this overnight. As a former IT Engineer we didn't have time to post anything, anywhere. It can be slow, long and laborious to identify, repair and resolve an issue.

BoreOfWhabylon · 08/02/2019 10:45

I also have 2 BoreOfWhabylons in my username history. There's a few other nicknames in there that I use occasionally - Christmas etc - but they aren't duplicated.

Haven't changed my password and won't do so (yet) as people seem to be getting locked out when they do.

No email as yet

And I agree with everything RedToothBrush has said

clairemcnam · 08/02/2019 10:42

I hadn't thought about adoptive parents. You are right their information being breached is extremely serious. I have seen adoptive parents posting wanting support with their child's traumatised behaviour.

Tooldemont · 08/02/2019 10:40

Mumsnet grosses around 5 million every month, and doesn't employ many people.

Their response to this is pathetic.

Roomba · 08/02/2019 10:38

I really don't think it is unreasonable for a site that has hundreds of thousands, if not millions, of users to have 24hr tech support! It's not some single parent running a little website from their kitchen table here - Mumsnet can afford to pay staff to work at night ffs. And you don't need to ask some poor soul to work a 24 hour shift to achieve this. You can just, you know, employ more staff? And ask some of them to work the night shift every day? Hmm

There can be serious issues with people's data if it gets into the wrong hands. Just because MN doesn't hold your credit card details doesn't mean someone's life couldn't be seriously fucked up if the wrong person accessed their private messaging details, namechange history etc. There was a poor girl and her mother on a TV documentary the other night who had to move areas again because her father pieced together which school she attended from a small piece of data posted online in error. Adoptive parents use the site - many of their children's details must stay confidential for their safety. People post about private medical issues on here that they wouldn't want linking to their email address and rl identity. I don't think you can say 'no harm done' here wth a straight face.

sprucegrove · 08/02/2019 10:37

I think what is happened is far worse than a hack. Everyone knows that sophisticated hackers hack some sites. And that having great security does not always stop that.
This is different. This is internal incompetence.
If this was a forum where people really only do talk about recipes and tv that would not be a big deal. But there are a lot of people here seeking advice about incredibly sensitive situations.

PetuliaBlavatsky · 08/02/2019 10:35

@C8H10N4O2 Mumsnet have been in touch with me directly about the random usernames I have in my keychain, I assume they'll update when they've got some more info.

IwantedtobeEmmaPeel · 08/02/2019 10:27

Bowlofbabelfish thank you for that, appreciate your advice.
I will be on to Mumsnet to see if I can get a direct answer, but actually seriously thinking of deactivitating my Mumsnet account.

Cbatothinkofaname · 08/02/2019 10:22

IceRebel- yes that ‘these things happen, no harm done’ post!

Dear god. Like that poster had JustineMumsnet round for a cuppa and she’d accidentally spilt some on the carpet.

What world do some posters live in that they see MN like this?!

KataraJean · 08/02/2019 10:18

Thanks to the posters who replied on duplicate user names Flowers

IceRebel · 08/02/2019 10:17

Just look, obviously there was no need for me to bring the toilet into this Grin

IceRebel · 08/02/2019 10:16

There’s a real risk here that some people are side stepping the issue and minimising it as some unavoidable little mistake.

I wholeheartedly agree with this, just loo at the 2nd post on this thread

Thank you for being so open and transparent.

These things happen, no harm done.

Some people are really minimizing the severity of the data breach.

Also still no email here, and i'm wondering how many people are going to miss this thread as they ignore stickies. I still think MNHQ need to have a pop up which has a link to this thread, to make sure all users are aware of this issue.

loobyloo1234 · 08/02/2019 10:09

Dear Lord. The previous nine hours were midnight until 9am.

Imagine a bank said this if there was a security breach with their own systems Hmm sorry guys, just having 9 hours off to have a sleep

Cbatothinkofaname · 08/02/2019 10:07

Floofy- don’t blame yourself for MN’s incompetence.

Like I said, I created a new email account after the last debacle, and use it only for MN, but I wouldn’t blame anyone else or say they were being naive if they’re using an email address with their name, or one which they use for other purposes.

There’s a real risk here that some people are side stepping the issue and minimising it as some unavoidable little mistake. This is seriously crap, and after the last massive data breach you’d think MN would take their responsibilies seriously.

The matey jokes about having a gin etc suggest that some users do really fit that stereotype- that MNers are all a bunch of middle class middle aged women with too much time on their hands who treat the forum like ‘JustineMumsnet’ is their bezzie and oh dearie me it’s all a bit of a palaver.

Fuck sake, there are vulnerable users on here who have bared their soul and deserve better.

JaneJeffer · 08/02/2019 10:04

I might put a photo of mine on my profile to scare away anyone who tries to hack my account.

RedToothBrush · 08/02/2019 10:03

Agree with PP someone should have been on shift overnight to respond to questions - its pretty poor that you persist in volunteers for the night shift the day after major data issue which is still not even fully defined.

Disagree with this. Its a complex issue that should be dealt with by someone senior who knows what they are talking about.

Otherwise you get into the situation of conflicting info going out, people getting more confused than they are and getting upset at that.

There should have been a better explanation yesterday and a FAQ put together for the overnight club with a message to say that someone would be back at X time to deal with queries. I'm sure that wouldn't satisfy many but I do think it reasonable.

It's better to have senior people on board for the initial incident and then let them rest and be back in during working hours to deal with on going fall out then.

MN isn't a large company. It's a medium sized one, and people need to take this on board even if they don't like it. I think they need to sharpen up, but I think some stuff said is unrealistic and many people should be a lot more worried about what goes on at multi national huge corporations with their data as people are getting away with a whole lot more without scrutiny.

The whole data industry needs a kick up the arse and people need better training. But without the law being properly enforced it's small fry like MN who get hung out to dry over these issues and not people who are abusing it on an epic scale.

FloofyCatLovesPerfume · 08/02/2019 10:01

But there is no need to be so fucking patronising shivering Hmm feel free to delete your account if you feel so patronising and superior to other MNers.

Bowlofbabelfish · 08/02/2019 10:01

I'm concerned that I've had an email from Mumsnet about this matter but not sent to the email that is registered with my Mumsnet account and to which Mumsnet have always sent emails before. They have sent an email to my hotmail account which I don't use for Mumsnet - what is happening here?

If you've never used that email in any comms with MN, the only explanation is data linking via one of the third party vendors they use.

If that’s what’s happened it’s a VERY big deal, and absolutely illegal. You need to follow up on that as a matter of urgency, because it’s capable of linking your account here to almost any other online presence you have.

Apologies for Atting you @iwantedtobeemmapeel but this is potentially serious and needs follow up

Roussette · 08/02/2019 09:59

Headline from The Register.

"Mumsnet data leak: Moaning parents could see other users' privates after cloud migration"

Not sure I want to see anyone's privates! Or them see mine!

FloofyCatLovesPerfume · 08/02/2019 09:59

Re the password change, it seemed not be saving it for me - I checked my emails and you had to click on a link to confirm it, then it changed.

If MNHQ confirm it was a system error allowing MNers to see other accounts that is bad, but IMO nowhere near as bad as it being hacked by a third party with malicious intent (especially given the recent threats to doxx MN and other generally menacing threats).

What I have taken from this is to clear my inbox/sent items every time I send/receive a message, and change my associated email to one that doesn't have my RL name in it. On reflection, this is my fault for not doing this previously.

I was going to delete my account but having been here over a decade there would be so many deleted posts, especially if we all did it. We all know how annoying it is reading a classics thread for example, with half of it missing!

I myself have been a bit naive but the reason my inbox had messages is that I have (for example) swapped items and supportive PMs with MNers I have known a very long time. I also used to post a lot in the SN section and would like my posts to remain in case anyone in a similar position finds them useful (not bigging myself up, it's a niche condition!) I also post in FWR (under NCs) and think it's important women continue to speak out and MN is a more liberal platform than the majority.

So on balance, if I reduce my own risks and am sensible, I prefer to keep using MN than not plus what would I do all day and RL people are sick of talking about cats Grin