The incident was identified after a member of staff’s email account was compromised and a malicious link was sent from the account as a result of a phishing attack.
The controller responsible for processing the personal data was the Committee for Education, Sport & Culture.
The email account was first compromised on 3 June and remained accessible to an unauthorised third party over the course of a month.
‘During that time some personal data held within the account – including names, addresses, dates of birth and some medical information of 74 individuals (a mixture of adults and children) – were accessed,’ Education director Nick Hynes confirmed yesterday.
‘We understand this news will be worrying for those involved, and we have written directly to them with further information, practical guidance and ways to seek further support.
‘Safeguarding the information entrusted to us is a responsibility we take extremely seriously, and we are committed to learning from this incident.’
One parent, who asked to remain anonymous, said she was extremely concerned when she received the letter informing her there had been a breach involving her child’s personal data.
‘I called them to ask for more information on what was going on and what data could have been seen about my child and they said someone will call me back,’ she said.
‘It makes my blood boil but they close ranks when you try to complain.’
She confirmed that no one had yet called her back.
Data protection commissioner Brent Homan confirmed that the ODPA had received a breach incident report from ESC.
‘The breach includes special category health data and children’s data,’ he said.
‘We have been in close contact with the organisation regarding their notification and safeguard obligations. Any affected individuals with concerns may submit a complaint to our office. Given the matter is ongoing we are not commenting further at this time.’
The States digital and technology team found no evidence of information being taken out of the Education IT environment and said that technical steps have been taken to ensure the security of the compromised account.
In the letter to parents, the States data protection team acknowledged that parents may experience concern about any onward sharing of personal information.
‘As a result of this breach, the controller is working closely with the States of Guernsey digital and technology team and their data protection officer to review the operational processes to improve data handling. This includes the implementation of improved cyber security measures to prevent phishing attacks and refresher training for staff,’ it said.
‘Our investigation has found no evidence that any information was exfiltrated or otherwise removed from the Education IT environment.’
It has not been explained why the 74 people were targeted or why their details were apparently held together.
Parents have been advised to stay vigilant for any unexpected communications such as emails, calls, texts or letters that request personal or financial information.
They should also be cautious of any correspondence that appears to come from a trusted organisation, but seems unusual or unexpected, and if any individual gets in contact claiming to represent a healthcare provider, school or government service, their identify should be verified before any information is shared.