Full Report
NRW says it has found no evidence data was misused after spreadsheet published in error five years ago
Analysis Summary
# Incident Report: Natural Resources Wales Diversity Data Disclosure
## Executive Summary
Natural Resources Wales (NRW) inadvertently disclosed sensitive diversity data belonging to approximately 2,000 current and former employees via a Freedom of Information (FoI) request response. The breach, which occurred in 2021 but was only recently addressed, involved the publication of an Excel spreadsheet containing special category personal data on a public-facing website. There is currently no evidence of data misuse, though the information remained exposed for several years.
## Incident Details
- **Discovery Date:** September 2024 (Approximate, based on reporting date)
- **Incident Date:** 2021 (Publication date); Data covers 2013–2018
- **Affected Organization:** Natural Resources Wales (NRW)
- **Sector:** Public Sector / Environmental Regulator
- **Geography:** Wales, United Kingdom
## Timeline of Events
### Initial Access
- **Date/Time:** 2021
- **Vector:** Human Error / Freedom of Information (FoI) Request
- **Details:** An employee or department fulfilling a FOI request failed to properly redact or sanitize a spreadsheet before publication.
### Lateral Movement
- **N/A:** This was not a cyberattack involving unauthorized network penetration; it was a misconfiguration/disclosure incident.
### Data Exfiltration/Impact
- **Details:** Sensitive "special category" data was published to a public website. The data included ethnicity, disability status, religion/belief, sexual orientation, Welsh language ability, and caring responsibilities for ~2,000 staff members.
### Detection & Response
- **Detection:** Discovered in late 2024 (Method of discovery not disclosed by NRW).
- **Response actions taken:** Information removed from the host website; deletion confirmation obtained; Information Commissioner’s Office (ICO) notified; internal investigation launched.
## Attack Methodology
- **Initial Access:** Misconfiguration (Public disclosure of internal records).
- **Persistence:** N/A.
- **Privilege Escalation:** N/A.
- **Defense Evasion:** N/A.
- **Credential Access:** N/A.
- **Discovery:** Publicly accessible URL.
- **Lateral Movement:** N/A.
- **Collection:** Accidental aggregation of HR data into a public-facing document.
- **Exfiltration:** Direct publication by the organization itself.
- **Impact:** Unauthorized disclosure of sensitive personal information.
## Impact Assessment
- **Financial:** Potential for regulatory fines from the ICO under UK GDPR.
- **Data Breach:** Exposure of sensitive diversity data for ~2,000 individuals.
- **Operational:** Diversion of resources for incident response and process auditing.
- **Reputational:** Public apology issued; negative media coverage regarding the "blunder."
## Indicators of Compromise
- **Network indicators:** N/A.
- **File indicators:** Spreadsheet containing diversity monitoring data (2013-2018).
- **Behavioral indicators:** Inadvertent publication of hidden tabs or unredacted columns in Excel files.
## Response Actions
- **Containment:** The spreadsheet was removed from the third-party website.
- **Eradication:** Obtained confirmation that the data was permanently deleted from the external host's cache/servers.
- **Recovery:** NRW is reviewing internal controls and notifying affected current/former staff where possible.
## Lessons Learned
- **Redaction Failures:** Standard "hiding" of columns or rows in Excel is insufficient for data sanitization; data must be physically removed or flattened.
- **Audit Gaps:** The breach went unnoticed for approximately three years, suggesting a lack of periodic auditing of published FoI responses.
- **Human Error:** Sensitive HR data should be subject to a "four-eyes" review process before being released externally.
## Recommendations
- **Technical Controls:** Implement automated Data Loss Prevention (DLP) tools to scan FoI responses for PII (Personally Identifiable Information) before they are sent or uploaded.
- **Process Improvement:** Transition from providing raw spreadsheets to providing data in non-editable formats (like PDF) or sanitized CSVs only after rigorous validation.
- **Training:** Provide specialized GDPR and data sanitization training for staff handling Freedom of Information requests.
- **Monitoring:** Conduct a retrospective audit of all FoI responses published in the last five years to ensure no other sensitive datasets are exposed.