Jersey Financial Services Commission registry flaw exposed 66,806 records
- Organization
- Jersey Financial Services Commission (JFSC)
- Exploit
- Misconfiguration
- Industry
- Financial Regulator
The Jersey Financial Services Commission, the financial services regulator for the British Crown Dependency of Jersey, disclosed on 7 March 2024 that a flaw in its Registry system had exposed personal data.
The commission said it detected the vulnerability on 23 January 2024. According to the regulator, a misconfiguration in the third-party supplied Registry platform allowed application programming interface requests to bypass the filtering that separates public records from restricted ones, so altering a web address reference could return data that was not meant to be visible. The system had been in place since January 2021, meaning the weakness had existed for about three years before it was found.
The exposed information consisted of non-public names and addresses. The commission said the records did not link individuals to registered entities or to roles they held, that its corporate network was not compromised, and that a forensic review conducted with an independent cyber security partner found no sign the data had surfaced on the dark web. Of roughly one million records held in the Registry, 66,806 individuals had their name and address accessed, and the commission wrote directly to 2,477 people it assessed as facing higher risk.
The Jersey Office of the Information Commissioner opened an investigation. External Relations Minister Ian Gorst separately commissioned an independent review of whether the response had been appropriate.