General election 2019: Labour Party hit by second cyber-attack
12 November 2019
Election 2019
Video caption
Jeremy Corbyn: "A cyber attack against a political party in an election is suspicious"
Labour is reportedly suffering a second cyber-attack after saying it successfully thwarted one on Monday.
The party says it has "ongoing security processes in place" so users "may be experiencing some differences", which it is dealing with "quickly".
The Distributed Denial of Service (DDoS) attack floods a computer server with traffic to try to take it offline.
The BBC's Gordon Corera has been told Monday's attack was not linked to a state.
Earlier, a Labour source said that attacks came from computers in Russia and Brazil.
Our security correspondent said he had been told the first attack was a low-level incident - not a large-scale and sophisticated attack.
A National Cyber Security Centre spokesman said the Labour Party followed the correct procedure and notified them swiftly of Monday's cyber-attack, adding: "The attack was not successful and the incident is now closed."
Meanwhile, Labour has denied that there has been a data breach or a security flaw in its systems after
the Times reported the party's website had exposed the names of online donors .
Following reports of a second cyber-attack, a Labour Party spokesperson said: "We have ongoing security processes in place to protect our platforms, so users may be experiencing some differences. We are dealing with this quickly and efficiently."
ADVERTISEMENT
A message on the site on Monday said it was experiencing issues "due to the large volume of users".
Video caption
EXPLAINED: What is a DDoS attack?
Labour leader Jeremy Corbyn said Monday's cyber-attack was "very serious" and also "suspicious" because it took place during an election campaign.
"If this is a sign of things to come, I feel very nervous about it," he said.
In a letter sent to Labour campaigners, Niall Sookoo, the party's executive director of elections and campaigns, said: "Yesterday afternoon our security systems identified that, in a very short period of time, there were large-scale and sophisticated attacks on Labour Party platforms which had the intention of taking our systems entirely offline.
"Every single one of these attempts failed due to our robust security systems and the integrity of all our platforms and data was maintained."
Labour's general secretary Jennie Formby said on Twitter the attack was a "real concern" but she added she was proud of the party's staff who "took immediate action to ensure our systems and data are all safe ".
Emily Orton, from Darktrace, an AI company for cyber-security, told BBC Radio 4's The World at One: "Really this is the tip of the iceberg in terms of the types of threats that, not just the Labour Party, but all political parties are going to be without a doubt experiencing on a daily basis."
"I think anyone involved in politics and in government need to be preparing themselves for a lot more stealthy, sophisticated attacks than this," she added.
Donors leak
By Leo Kelion, Technology desk editor
The Times has revealed that Labour exposed the names of people who had donated money via an online tool.
The details could be found via an RSS web feed generated by the site's code, which most browsers provide a way to inspect.
In most cases the information was limited to the donors' first names and the sums given.
But because some people had mistakenly added their surname to the first name input box, this too was disclosed.
Labour denies this represented a security flaw or that a reportable data breach had occurred. It also believes that only a small number of full names were exposed.
However, it made changes to shut down the RSS feed last night.
"The Labour Party takes its responsibilities for data protection extremely seriously," a spokesman said.
"If any concerns are raised, we assess them in line with our responsibilities under GDPR [General Data Protection Regulation ] and the Data Protection Act."
The Information Commissioner's Office told the BBC: "We will not be commenting publicly on every issue raised during the general election.
"We will, however, be closely monitoring how personal data is being used during political campaigning and making sure that all parties and campaigns are aware of their responsibilities."