BBC Pension Scheme breach exposed data on more than 25,000 members

Organization
BBC
Exploit
Hacking
Industry
Broadcasting

The BBC told members of its pension scheme in late May 2024 that their personal details had been copied from an online storage service in what it described as a data security incident.

The scheme said it was alerted on May 21, 2024 and that files relating to 25,290 current and former employees were involved. The records included names, dates of birth, sex, National Insurance numbers and, for some members, home addresses. The BBC said the files did not contain bank details, other financial information, telephone numbers, email addresses, usernames, passwords or health information, and that the pension scheme website and member portal were not involved.

Catherine Claydon, chair of the BBC Pension Trust, said there was no evidence of a ransomware attack and no sign that the copied files had been misused. The corporation said the source of the incident had been secured, that additional monitoring had been put in place, and that internal and external specialist teams were working to establish how it happened. The incident was reported to the Information Commissioner's Office and to the UK pensions regulator.

Members were offered two years of free credit and web monitoring and were advised to be alert to unsolicited approaches seeking personal information. The BBC did not identify the storage service or explain how it had been reached, although a security consultant quoted by IT Pro suggested a repository with incorrectly configured security was a plausible explanation.

Sources