Hacked UK Government Web Sites

P. John made this Freedom of Information request to Cabinet Office

The request was partially successful.

From: P. John

20 March 2010

Dear Cabinet Office,

I understand that the "Information Security and Assurance (IS&A) is
a unit within the UK Government's Cabinet Office providing a
central focus for Information Assurance (IA) activity across the
UK".

Please could you disclose to me any assessment made by the IS&A
unit of the number of UK Government web sites currently hijacked by
Viagra/Cialis/Levitra and other online meds scams?

I include some examples below.

Google presently reports 21,400 UK Government web pages with the
term Viagra, 18,200 carrying the term Cialis, and 12,600 with the
word Levitra.

Could you also disclose any plans or strategy to remediate affected
UK Government sites?

Could you also confirm to me recent press reports that the Cabinet
Office intended to make all UK Government services available
through a single web portal using a personal identifier?

Yours faithfully,
P John

Westminster Council;
http://www3.westminster.gov.uk/wish/WISH...

Shetland Islands Datasharing for Community Planning (nb links are
hidden within the HTML of the page, view page source)
http://www.shetland.gov.uk/datashare/Dat...

Teachernet
http://www.teachers.gov.uk/eventscalenda...

Lewisham Council
http://www2.lewisham.gov.uk/lbl/Events/e...

Google Search for Cialis on UK Government Websites
http://www.google.co.uk/search?q=site%3A...

Google Search for Viagra on UK Government Websites
http://www.google.co.uk/search?q=site%3A...

Link to this

Cabinet Office

23 March 2010

CABINET OFFICE REFERENCE: FOI274565

Dear Mr John,

Thank you for your request for information. Your request was received on
22/03/2010 and is being dealt with under the terms of the Freedom of
Information Act 2000.

In some circumstances a fee may be payable and if that is the case, I will
let you know the likely charges before proceeding.

If you have any queries about this letter, please contact me. Please
remember to quote the reference number above in any future communications.

Yours sincerely,

FOI Team
Cabinet Office
E: [1][Cabinet Office request email]

The Cabinet Office computer systems may be monitored and communications
carried on them recorded, to secure the effective operation of the system
and for other lawful purposes.

show quoted sections

Communications via the GSi may be automatically logged, monitored and/or
recorded for legal purposes.

References

Visible links
1. mailto:[Cabinet Office request email]

Link to this

Cabinet Office

7 April 2010


Attachment document2010 04 07 143636.pdf
98K Download View as HTML


Dear Mr John,

Please find attached to this email a letter in response to your recent Freedom of Information request.

Many thanks

Information Security & Assurance Team
Cabinet Office

show quoted sections

Link to this

From: P. John

13 April 2010

Dear Cabinet Office,

thank you for your reply to my FoI request.

I regret, with tens of thousands of public web pages clearly
compromised by poor security measures, I doubt that the Government
would ever be capable of operating a site such as the proposed
MyGov securely.

If there is any way for me to exercise discretion, I would choose
that none of my personal information is ever presented online in
this way.

Can I assume you will also indemnify those people whose information
is presented on such a site from the costs and inconvenience caused
by identity theft, or hacking?

Yours faithfully,

P. John

Link to this

Cabinet Office

20 April 2010

Dear Mr John,

I refer to you email of 13 April.

Please confirm if you require any further information from us in
accordance with the Freedom of Information Act. It is not clear from the
last paragraph in your email whether you are making a statement or asking
a further question. If it is the latter please note that a `valid' request
under the Act is one that seeks to see recorded information held by the
public authority, such as information on a specific issue, or process, not
one that asks for opinion or seeks answers or calculations.

I propose to take no further action unless I hear back from you.

Kind regards,

Yasmine Edwards

FOI Team

Cabinet Office

Tel: 020 7276 2473

The Cabinet Office computer systems may be monitored and communications
carried on them recorded, to secure the effective operation of the system
and for other lawful purposes.

show quoted sections

Communications via the GSi may be automatically logged, monitored and/or
recorded for legal purposes.

Link to this

Things to do with this request

Anyone:
Cabinet Office only: