Meet the Other Phone. Protection built in.

Meet the Other Phone.
Protection built in.

Buy now

Please or to access all these features

Feminism: Sex and gender discussions

Mumsnet data breach

67 replies

PronounssheRa · 07/06/2022 07:45

Reposting this from site stuff and chat as here is where a lot of reporting of posts happens

www.mumsnet.com/talk/site_stuff/4564026-change-in-format-of-response-to-report-emails

www.mumsnet.com/talk/_chat/4564131-another-mumsnet-data-breach

We had a temporary glitch with 'Report this post' for a short time today which meant the email of the person reported was included in the report and in a few cases in responses to those reports. This applies to a very small number of users and we'll be contacting them shortly to let them know. Our DPO has been informed and on his advice we'll report it the ICO if appropriate. Please be assured the issue is now fixed. We will of course be examining how it happened to ensure it never happens again. We're really sorry for any concern caused.

OP posts:
Slothtoes · 07/06/2022 08:36

Oh for fucks sake. When did this problem start please?

Lovelyricepudding · 07/06/2022 08:40

I use a burner email for this reason. The only problem is I quickly forget my login details so never see any emails sent there...

nicerucksack · 07/06/2022 08:41

Thanks @Ereshkigalangcleg I've deleted it but this is very worrying. Somewhat casual response by MN to this, I must say.

drinkingwineoutofamug · 07/06/2022 08:43

@nicerucksack did your email of thanks for the report come with a 'how did we do' option?

drinkingwineoutofamug · 07/06/2022 08:44

.

Mumsnet data breach
TeenPlusCat · 07/06/2022 08:47

nicerucksack · 07/06/2022 08:41

Thanks @Ereshkigalangcleg I've deleted it but this is very worrying. Somewhat casual response by MN to this, I must say.

I saw a similar comment on another thread.

What response do you expect from MN?

They are notifying the people whose data they have breached.
They have rectified the fault.
They have made their data protection person aware and will notify the relevant office as needed.

Advertising it far and wide surely just makes it more likely that breeched data will be collected and used?

Isn't it it better to take the steady steps to minimise harm, and only then make more general announcements?
Do you want Justine to appear on BBC News at 10 wearing sackcloth and ashes?

nicerucksack · 07/06/2022 08:51

@drinkingwineoutofamug yes it did.

TurnstileSpinStyle · 07/06/2022 08:52

As ever with MNHQ data breaches, it doesn’t help to be left hanging not knowing whether one has been personally affected or not - and by precisely what and how.

Really poor.

Ereshkigalangcleg · 07/06/2022 08:53

People were obviously going to find out about it, though, weren't they. They have asked questions which haven't been answered about the time period in question.

Obviously people have concerns, particularly due to the reporting levels on this board, and some are not happy with how other data protection issues were dealt with in the past. I don't think the "let's hope no one notices this serious data breach" approach is a particularly good one, personally.

nicerucksack · 07/06/2022 08:54

TeenPlusCat · 07/06/2022 08:47

I saw a similar comment on another thread.

What response do you expect from MN?

They are notifying the people whose data they have breached.
They have rectified the fault.
They have made their data protection person aware and will notify the relevant office as needed.

Advertising it far and wide surely just makes it more likely that breeched data will be collected and used?

Isn't it it better to take the steady steps to minimise harm, and only then make more general announcements?
Do you want Justine to appear on BBC News at 10 wearing sackcloth and ashes?

What I would like is more of an indication that they are taking these breaches seriously. This isn't the first time something like this has happened. One single response, hidden in the middle of a thread started by a poster, is not enough.

TeenPlusCat · 07/06/2022 09:00

Yes, I do understand that. I just don't think calling it 'casual' is fair.

Surely the first priority is notifying the actual people effected, understanding the scope etc, not to broadcast details across the whole of MN?

A thread like this on this board is positively asking for monitors to check their report post emails to see what data they can glean? Especially as they often don't otherwise use MN?

I'm not saying this isn't serious, far from it. But if a Bank has a giant hole in it, you fix the hole first before going out of your way to advertise the hole to all the criminals in the area. (not a great analogy)

Ereshkigalangcleg · 07/06/2022 09:03

Once it's been discovered, transparency and clear information is needed. You can't put the genie back in the bottle, people are obviously going to want to talk about it and the less information they have the more they will want to do so, and the more concerned they will be. As I said, expecting people not to talk about it and want to see their own email reports is unrealistic.

letsallchant · 07/06/2022 09:05

The whizzy new site on its new platform racks up another success. Lovely to know it's such an improvement on the old one.

Waitwhat23 · 07/06/2022 09:06

And I thought I was possibly being over cautious using a burner email address for here and other platforms! Glad I did now.

echobeech · 07/06/2022 09:10

I've name changed and ditched my previous account and email. The TRAs will have harvested as much as they could and that information will now be being shared in their telegram and discord servers.

It doesn't help that MNHQ don't let a poster know that their post has been reported, a function that is badly needed here.

Thanks Mumsnet.

WorkingItOutAsIGo · 07/06/2022 09:10

Yep, always use a burner mail for Mumsnet. proton Mail is a good one.

PronounssheRa · 07/06/2022 09:14

What MN should have done is test any area or functions of the site where changes have been made before going live. They don't appear to have done that with the report function.

What they should do now is clarify the time period this breach occurred so posters can work out if they were impacted.

I'm not going to apologise for flagging the breach up here.

I'm not saying this isn't serious, far from it. But if a Bank has a giant hole in it, you fix the hole first before going out of your way to advertise the hole

They have fixed the hole, sadly not before data was leaked. That particular genie can not be put back in the bottle.

OP posts:
TurnstileSpinStyle · 07/06/2022 09:20

Well exactly.

MNHQ/Justine said last night they’d fixed the breach.

Now we’re trying to understand who got robbed, and how bad it is for the individuals who will need to act.

How do we KNOW everyone affected has been contacted?

InsideNoNine · 07/06/2022 09:21

I think the Helen Joyce video has ramped up the vitriol, I've name-changed too. Be wary we could be in for a few bumpy weeks.

tabbycatstripy · 07/06/2022 09:24

This is awful. I use an email address for MN that I don’t use for anything else. I won’t be reporting any more posts either.

echobeech · 07/06/2022 09:30

tabbycatstripy · 07/06/2022 09:24

This is awful. I use an email address for MN that I don’t use for anything else. I won’t be reporting any more posts either.

Good idea, I think it's better to let them stand

echobeech · 07/06/2022 09:31

echobeech · 07/06/2022 09:30

Good idea, I think it's better to let them stand

#the site's still glitching#

Good idea, it's probably better to let them stand anyway - I think some posts are created by TRAS looking for them to be deleted so they can screenshot for twitter.

NotBadConsidering · 07/06/2022 09:51

Yes I use proton mail only for Mumsnet too. Not a sign of confidence really is it?🤨

BertieBotts · 07/06/2022 10:25

I checked and my most recent report email was from 16 May and only includes my email and full name (which now I think about it is a bit weird??) not the person reported.

pontefractals · 07/06/2022 10:32

echobeech · 07/06/2022 09:30

Good idea, I think it's better to let them stand

From what I've read, the problem isn't with you reporting posts, it's with your posts being reported, possibly vexatiously, and the reporter getting your email address. Fun times.