Government accidentally leaks counter-terrorism tools via Trello

Hundreds of sensitive documents also revealed thanks to poor security settings - report

Government

Details about the inner workings of the UK government have been accidentally leaked online, thanks to unsecure use of a web-based project management tool, it is claimed.

Hundreds of confidential documents from the Cabinet Office and Home Office were reportedly available via a Google search, including details of government anti-terrorism tools and instructions for how to go about obtaining entry passes for government buildings.

The calendar appointments of civil servants were also allegedly accessible, allowing hackers to potentially trace who government figures are meeting and what they are meeting about.

The trove even included names, phone numbers and personal email addresses for top civil servants like the prime minister's head of cross-government business engagement, potentially leaving senior government figures open to phishing attacks like the one that allegedly allowed Russian hackers to sway the US elections.

The alarming news was revealed by a Sunday Telegraph investigation, which found that the information - which may have been available for up to four years - was leaked via poor configuration and use of Trello, a cloud-based project management tool.

Trello is commonly used to manage the workflows of individual teams within an organisation, using a system of kanban-style 'boards'. By default, these boards are set to 'private', so that only members of the relevant team can access them. They can, however, be set to 'public', which allows anyone with the correct link to access them.

Crucially, it also allows those boards to be indexed by search engines like Google, which means that searching for certain keywords found within the boards - such as government departments, topic areas or civil servants - would result in the boards themselves (as well as specific files and task cards within them) showing up on a Google search.

The Sunday Telegraph's investigation found that at least ten government Trello boards were set as publicly accessible. These boards have now been switched to private, but certain parts of their contents remain accessible via Google searches.

The use of Trello within government is part of a wider digital transformation drive, encouraging civil servants to use mobile, cloud-based collaboration and productivity tools, rather than relying on older, less agile methods like email. The drive was initially started in 2013 by the Government Digital Service, and included tools like Skype and Twitter in addition to Trello.

"We take data protection very seriously, and impress upon all government departments to exercise best practice and implement suitable measures to ensure data is secure when using platforms such as Trello boards," a government spokesperson told IT Pro

"The Government Digital Service and Trello are working with government departments to ensure any data breached is made secure. Trello has offered to make all government accounts private, to ensure data is better protected in the future."

Featured Resources

The ultimate law enforcement agency guide to going mobile

Best practices for implementing a mobile device program

Free download

The business value of Red Hat OpenShift

Platform cost savings, ROI, and the challenges and opportunities of Red Hat OpenShift

Free download

Managing security and risk across the IT supply chain: A practical approach

Best practices for IT supply chain security

Free download

Digital remote monitoring and dispatch services’ impact on edge computing and data centres

Seven trends redefining remote monitoring and field service dispatch service requirements

Free download

Recommended

30 countries announce crackdown on ransomware payments
ransomware

30 countries announce crackdown on ransomware payments

15 Oct 2021
Senators seek to reform Section 230 protections
Policy & legislation

Senators seek to reform Section 230 protections

14 Oct 2021
Biden is confident in the nation’s cyber security efforts
cyber security

Biden is confident in the nation’s cyber security efforts

4 Oct 2021
Dual citizen sentenced to 11 years for role in North Korean crypto hacking scheme
hacking

Dual citizen sentenced to 11 years for role in North Korean crypto hacking scheme

10 Sep 2021

Most Popular

Apple MacBook Pro 15in vs Dell XPS 15: Clash of the titans
Laptops

Apple MacBook Pro 15in vs Dell XPS 15: Clash of the titans

11 Oct 2021
Best Linux distros 2021
operating systems

Best Linux distros 2021

11 Oct 2021
HPE wins networking contract with Birmingham 2022 Commonwealth Games
Network & Internet

HPE wins networking contract with Birmingham 2022 Commonwealth Games

15 Oct 2021