Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

My data has been breached

261 replies

Simbaya · 07/06/2022 16:05

Respond please.

OP posts:
felineweird · 07/06/2022 23:15

I pray to our Lord (take the piss as you will) for all parties here. Appalling comments from the OP but Shocking from MN! @JustineMumsnet you have given the world someone's comments when you have also dished out their email address to 3 people! I get why the OP is shitting it but mumsnet may have made this woman a victim. FWIW I agree with your opinion of said poster but how could you?!

Johnnysgirl · 07/06/2022 23:06

NippyWoowoo · 07/06/2022 23:05

It's already on Reddit 🤨. Well done, Justine.

Seeing as Reddit and MN have many users in common, it's hardly shocking. There's a sub dedicated to it.

I meant who the op is.

Sortilege · 07/06/2022 23:05

treesurgeonsarefemaletoo · 07/06/2022 21:37

It’s not just the feminist section at risk, I lurked on a sub which doxxed several users of mumsnet just because they disagreed with them. Those who mock people being upset are unbelievably arrogant about what some oddballs will do with private information. It’s a sport for some inadequate creatures.

Oh bloody hell. Them. They will be having a field day with this cock up, no doubt.

NippyWoowoo · 07/06/2022 23:05

It's already on Reddit 🤨. Well done, Justine.

Seeing as Reddit and MN have many users in common, it's hardly shocking. There's a sub dedicated to it.

NippyWoowoo · 07/06/2022 23:02

kimblerk · 07/06/2022 22:55

i think Justine knows that posting the OP’s deleted posts makes it clear who she is (you don’t have to have been here for long to work it out) and knows that OP is generally disliked/ frequently deleted therefore people won’t care that her data has been breached as much as they would if she was a popular poster. Cheap shot from MNHQ

I think you think too highly of MN and the impact it has on people's lives. Despite being here every day and commenting regularly, I did not 'recognise' the OP, not her posts, certainly not enough to know whether or not she's 'liked'

But thanks for taking off another layer of the anonymity I guess

Johnnysgirl · 07/06/2022 22:58

kimblerk · 07/06/2022 22:55

i think Justine knows that posting the OP’s deleted posts makes it clear who she is (you don’t have to have been here for long to work it out) and knows that OP is generally disliked/ frequently deleted therefore people won’t care that her data has been breached as much as they would if she was a popular poster. Cheap shot from MNHQ

It's already on Reddit 🤨. Well done, Justine.

saraclara · 07/06/2022 22:57

SlatsandFlaps · 07/06/2022 21:31

It's not great no. But it's an email address. Not a phone number or house address so I do think you're overreacting just a bit. Calm down. MNHQ are taking this seriously (based on their posts on the other thread) and will deal with it

My email address is my real first and surnames@... The latter has an unusual spelling and I could pretty much instantly be identified and found in real life.

Mumsnet has made a huge error here.

Kerrrmieee · 07/06/2022 22:57

After seeing the posts I lost all sympathy. Nicely shared.

That said, blaming human error is even worse - surely it has to be automated following a report.

Any employee should not have access to anybody's personal information. This should be buried in a database so that any human likely to make an error can only see user22356 and user22356@mail

It is quite astounding that the tech is so basic and it sounds like users have been cc'd in to each other.

kimblerk · 07/06/2022 22:55

i think Justine knows that posting the OP’s deleted posts makes it clear who she is (you don’t have to have been here for long to work it out) and knows that OP is generally disliked/ frequently deleted therefore people won’t care that her data has been breached as much as they would if she was a popular poster. Cheap shot from MNHQ

GoodThinkingMax · 07/06/2022 22:35

The responses from @MNHQ are very unsatisfactory.

Anyone who's had her posts reported may well have had her email address disclosed to the post-reporter.

Given that we KNOW there is targeted reporting of posts in some areas of MN - especially FWR, by TRAs and MRAs, this is really problematic.

MNHQ seem quite blasé at this very basic breach of trust. No wonder no-one will pay for MN Premium.

carefullycourageous · 07/06/2022 22:26

ToastedCrumpetwithCheese · 07/06/2022 22:17

This is exactly the reason why I use a number of generic email addresses that don't contain my name for sites like this.

Yes, I do too because I am basically paranoid - but it does not help the OP and sites should be secure.

JamToastToday · 07/06/2022 22:22

NippyWoowoo · 07/06/2022 22:14

Exactly. I appreciate the transparency

Disagree, shouldn’t have been done without OP’s permission and has exposed her further. Not cool.

IssaBaby · 07/06/2022 22:21

The amount of people making light of this just goes to show just how ill informed some people are in this day and age.
Probably the same people who believe Facebook news is real news.

I wouldn't want even one person to know my personal email address without my permission let alone 3 from the vipers nest!

So sorry this has happened OP.

JamToastToday · 07/06/2022 22:20

HydraWater · 07/06/2022 22:16

The release of OPs email address is not good, at all.

However, I personally never use private email adresses for anything other than work or interraction with official government departments etc. I keep one email address separate and anonymous sounding for places like here and the other with my real name for officialdom. I thought everyone did that?

Amazing isn’t it that not everyone does what you do 🙄

BoreOfWhabylon · 07/06/2022 22:17

@LazyJayne Well said.

Idontgiveagriffindamn · 07/06/2022 22:17

What is the outcome you want? It’s is. A breach and it is personal data but it’s already happened and cannot be changed.
There has been an apology issued, all people affected contacted, an investigation into what happened and hopefully they have been truthful about what further measures will be put in place. They have also confirmed that they’ve reported themselves to the ICO.

I’m not saying what has happened isn’t upsetting but things like this do happen and they happen with more sensitive data as well usually down to human error / not following procedure.

The best thing to do for all concerned is to use it as a learning experience - what measures can we all put in place when signing up to forums / accounts. Whether that is to set up on anonymous email address that does not contain names or choose not to use mumsnet or something else.

It is a bit shitty to post the original comments but I get the thinking behind it. Wrong approach though.

ToastedCrumpetwithCheese · 07/06/2022 22:17

This is exactly the reason why I use a number of generic email addresses that don't contain my name for sites like this.

C8H10N4O2 · 07/06/2022 22:16

@JustineMumsnet

We emailed the affected users overnight offering to delete their posts, a retrospective name change or to change their email address. There are around 20 users affected

Can you please clarify how you have validated that list? Are you relying on logs or using logs of all replies to reports? (I'm assuming you have a timestamped audit trail).

It applied only to the emails/usernames of users who had posts reported (not to those doing the reporting). (Their details were included at the bottom of replies to the person who reported the post)

Why have email addresses started appearing at all? Replies in this type of system should keep all contact details blind both to reporter and moderator. That is a design choice which needed implementing and should have been picked up during data/security design. Is this another issues which is on the list to fix as a "glitch" of the upgrade?

We know how the error occurred - we obviously have checks and balances in place to stop this kind of thing happening and in two very clear ways the proper procedures weren't followed in this instance

If human beings can override procedures in two places without a check step them something is fundamentally wrong with the SDLC model. Config changes, particular those which could expose data should be both tested and automated and subject to review before deployment.

What has been put in place to stop procedures being overidden in future? We all remember the joy of the intern.

I'm really sorry this has happened and apologise wholeheartedly to all those who've suffered undue concern as a result

With the greatest respect, this statement is completely at odds with publicly posting the contents of the reports about one of your victims.

HydraWater · 07/06/2022 22:16

The release of OPs email address is not good, at all.

However, I personally never use private email adresses for anything other than work or interraction with official government departments etc. I keep one email address separate and anonymous sounding for places like here and the other with my real name for officialdom. I thought everyone did that?

treesurgeonsarefemaletoo · 07/06/2022 22:15

@SlatsandFlaps publish your email then? I have witnessed doxxing on a sub and it was unpleasant and harassing. Children’s names were mentioned and I believe were contacted. You clearly have no idea of the type of people who revel in this sort of thing.

carefullycourageous · 07/06/2022 22:15

Readtheroom · 07/06/2022 19:47

Why do you care that someone has your email address and name, unless its very unique? There's a million Emma Watsons and no one can really do anything with this information

This is very naive.

Anyway, the law is clear on data protection and the reasons it matters are widely understood.

NippyWoowoo · 07/06/2022 22:14

dreamingofspain · 07/06/2022 22:08

FWIW It’s pretty obvious to me why the reported posts were posted here by Justine - the OP has been on this thread claiming that the reports were malicious. Yes it could have been sent to the OP by email but then everyone else here wouldn’t have known that there was no malicious activity and would have worried about it. I’m not sure you can complain about a lack of info from MNHQ and then also complain when you get it.

Exactly. I appreciate the transparency

JemimaTiggywinkle · 07/06/2022 22:13

SlatsandFlaps · 07/06/2022 22:07

It wouldn't bother me at all to be honest because I've nothing to hide!

I'm also not fussed about being outed 🤷🏼‍♀️ Just doesn't bother me personally at all.

It might bother you if someone tweets that you’re a terrible person and publishes your name, address/workplace and threats of violence (usually rape).
You don’t need to have anything to hide.

RandomUser10093 · 07/06/2022 22:13

This reply has been withdrawn

This has been withdrawn by MNHQ at the poster's request.

Hawkins001 · 07/06/2022 22:13

I can understand why intelligence assets have a full cover when in the field.

Swipe left for the next trending thread