Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

2,000 users’ details taken in Fine Gael website breach

The party confirms that 2,000 details had their emails, mobiles and IP addresses taken, as the FBI is called in to investigate.

Updated, 19.55

FINE GAEL has emailed visitors to its website, advising them that their personal details were accessed, and may have been copied, by the Anonymous ‘hacktivist’ group that breached its site last night.

The party’s new website - launched just last Tuesday – was last night breached by two members of the collective, who manipulated the site’s commenting feature into displaying an Anonymous-branded holding page telling users that Fine Gael had “taken no measures to protect you”.

The FBI has been called in to investigate the breach by the US hosting firm ElectionMail, which hosted the site.

This morning, as the Data Protection Commissioner indicated he was investigating the breach, the party wrote to the website’s visitors – who were invited to give their names, email addresses, constituency details and phone numbers when they left comments – to inform them of the attack.

In an email seen by TheJournal.ie, the party said its site had been “professionally hacked” between the hours of 8pm and 12am last night.

The email read:

We were alerted this morning that the Anonymous Group was able to secure the database of the information submitted by you during the previous week…

As a result we have now taken the necessary action to report this “hacking crime” to the proper authorities including the Data Protection Commissioner and the Gardai.

This lunchtime the party said that around 2,000 users had seen their details – as well as their unique IP addresses – accessed; the Evening Herald had earlier reported that almost 4,000 comments have been left, but the Herald’s Kevin Doyle has since tweeted that a number of the comments were left by repeat visitors, thus reducing the overall number of persons affected.

Proving that Fine Gael had been selectively censoring messages submitted by users to the site, Anonymous provided Doyle with a copy of the data collected – data which included the details of Green Party TD Paul Gogarty, who had left a comment on the site.

The Herald also quotes a statement from Anonymous which describes Fine Gael as “a bunch of lying, deceitful men” and added that “all you people are interested in is your own back pocket”.

‘Not terribly complicated’

An online security analyst, who asked to remain unnamed, told TheJournal.ie that the attack was likely the work of what are called ‘script kiddies’, utilising a technique known as a ‘cross site scripting’ attack.

Such attacks, the analyst said, are “not terribly complicated” and are “usually easily defended against”.

At the time of writing, the website remained offline, with a holding page advising visitors that the site would remain unavailable “while we follow-up [sic] with the appropriate authorities to resolve this matter”.

The party’s traditional website, which had remained active at www.finegael.org while the temporary campaign website was active, has also been removed, and also redirects visitors to the notice about the Anonymous attack.

Overnight, the site had been taken down fully, and then replaced with a holding page assuring users that “the integrity of all the data collected” was “still intact, and was not accessed at any point by this outside entity”. Screengrabs of the site at various stages overnight have been posted on politics.ie and on the blog of Michele Neylon.

Anonymous is more widely known for its campaigns against the Church of Scientology, and more recently for having attacked the websites of companies like Visa, Mastercard and Paypal over those sites’ withdrawal of services to WikiLeaks.

Last week the site had come under further scrutiny when it was revealed that it was hosted in Miami, meaning that no political party in the Dáil had its main website hosted within Ireland.

The foreign-based hosting service had also raised concerns in the blogosphere about the Party’s compliance with the Data Protection Acts, and whether their transfer of personal data to a host outside of the EU was being done on a compliant legal basis

As a result, late last week the site was updated to include an opt-out where users could stop the party from retaining their details.

This afternoon Fine Gael senator Paschal Donohoe told RTÉ Radio’s News at One that the party “regretted” the security breach, but that the   website had fallen victim to a “formidable” outside presence.

Donohoe said the website had been hosted in the United States “for reasons in relation to bandwidth access, and also cost”.

Additional reporting by Susan Ryan.

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Close
Comments
    Install the app to use these features.
    Mute OggieThe4th
    Favourite OggieThe4th
    Report
    Apr 18th 2015, 6:55 PM

    I’ve also heard that Cadbury’s have hacked off one-fifth of Freddo the Frog .

    34
    Install the app to use these features.
    Mute Kevin Higgins
    Favourite Kevin Higgins
    Report
    Apr 18th 2015, 7:00 PM

    And our giving redundancies to their staff as they are moving operations to a cheaper country

    21
    Install the app to use these features.
    Mute Mary Ward
    Favourite Mary Ward
    Report
    Apr 19th 2015, 5:13 AM

    everybody is leaving. I am hoping to go myself and I am in the higher tax bracket. I stayed because i felt it served my country to pay tax and support others. I am now over it. It doesn’t serve me anymore. I am in debt and I would be better off elsewhere.

    19
    Install the app to use these features.
    Mute Mary Ward
    Favourite Mary Ward
    Report
    Apr 19th 2015, 5:14 AM

    and when I say debt, its minimum and I can pay it back. Not compared to the fraudsters that gambled. They have put me and many others in debt

    11
    Install the app to use these features.
    Mute Colin C
    Favourite Colin C
    Report
    Apr 18th 2015, 10:05 PM

    Dear Mr. Journalist. It’s “how quickly”, not “how quick”. When describing a verb, you use an adverb, not an adjective. I know that the internet likes to bugger with adverbs, particularly if it pertains to doing anything “direct”, but you, as indebted as you are to the English language for your living should be able to show that language just a modicum of respect.

    13
    Install the app to use these features.
    Mute YFG Account
    Favourite YFG Account
    Report
    Apr 18th 2015, 6:49 PM

    I wish wikileaks would stop invading other people’s privacy. It worries me to think what would happen if they started targeting business and political figures over here, not that there’s anything to hide of course.

    9
    Install the app to use these features.
    Mute Silent majority
    Favourite Silent majority
    Report
    Apr 18th 2015, 6:52 PM

    Fake account

    19
    Install the app to use these features.
    Mute Kevin Higgins
    Favourite Kevin Higgins
    Report
    Apr 18th 2015, 6:55 PM

    Fake account but some of the view expressed aren’t far off the YFG mentality

    25
    See 6 more replies ▾
    Install the app to use these features.
    Mute YFG Account
    Favourite YFG Account
    Report
    Apr 18th 2015, 6:55 PM

    I suppose Mr and Ms Majority really thought you looked like a silent when you were born?

    7
    Install the app to use these features.
    Mute Kevin Higgins
    Favourite Kevin Higgins
    Report
    Apr 18th 2015, 7:00 PM

    Silent majority who are you?

    14
    Install the app to use these features.
    Mute Suzie Sunsine
    Favourite Suzie Sunsine
    Report
    Apr 18th 2015, 7:09 PM

    Looks like Kevin and yfg are best buddies .. Interesting

    7
    Install the app to use these features.
    Mute YFG Account
    Favourite YFG Account
    Report
    Apr 18th 2015, 7:13 PM

    Suzie are you and davedunne the same person? You both seem a bit obsessed with me.

    1
    Install the app to use these features.
    Mute Suzie Sunsine
    Favourite Suzie Sunsine
    Report
    Apr 18th 2015, 7:22 PM

    Is that the best you could come up with ?

    6
    Install the app to use these features.
    Mute Kevin Higgins
    Favourite Kevin Higgins
    Report
    Apr 18th 2015, 7:23 PM

    I differ in policy to yfg on most issue. It’s a careerists clubs for most. Boosts the cv for various employers. I dislike yfg and would never vote FG after what they’ve done.

    18
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.
JournalTv
News in 60 seconds