Nuneaton and Bedworth Borough Council: Voters details leaked in council data breach

Nuneaton and Bedworth Borough Council: Voters details leaked in council data breach

Nuneaton and Bedworth Borough Council Leaks Personal Data of Nearly 3,000 Voters

On 27 July 2026, Nuneaton and Bedworth Borough Council accidentally exposed the personal data of 2,900 voters in the Arbury ward during its annual electoral roll update. The breach occurred when an email sent to residents included a link to a spreadsheet containing names, email addresses, and personalized security codes information that could allow unauthorized access to the council’s online voting system.

The council identified the error quickly and removed the exposed data, but not before the link was distributed. Tom Shardlow, the council’s chief executive, acknowledged the incident as an administrative error and confirmed that affected individuals had been notified. Those who did not receive a message were assured their data remained secure.

The council reported the breach to the Information Commissioner’s Office (ICO), which provided guidance on mitigation steps. While the council classified the leaked data as "low-level," Shardlow emphasized that any unauthorized disclosure was unacceptable and pledged to implement additional fail-safes to prevent future incidents.

The breach affected part of the annual canvass, a nationwide process where councils update voter registration details. With over 70,000 people registered to vote in Nuneaton and Bedworth, the council stressed that this was an isolated case and apologized for the oversight. No evidence has emerged of the data being misused.

Source: https://www.bbc.com/news/articles/cd0xvy47zkko

Nuneaton and Bedworth Borough Council cybersecurity rating report: https://www.rankiteo.com/company/nuneaton-and-bedworth-borough-council

"id": "NUN1785414326",
"linkid": "nuneaton-and-bedworth-borough-council",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '2,900 voters',
                        'industry': 'Public Administration',
                        'location': 'Nuneaton and Bedworth, UK',
                        'name': 'Nuneaton and Bedworth Borough Council',
                        'type': 'Government'}],
 'attack_vector': 'Administrative Error',
 'customer_advisories': 'Affected individuals notified; others assured their '
                        'data remained secure',
 'data_breach': {'data_exfiltration': 'No evidence of misuse',
                 'file_types_exposed': 'Spreadsheet',
                 'number_of_records_exposed': '2,900',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'Low-level (names, email addresses, '
                                        'personalized security codes)',
                 'type_of_data_compromised': 'Personal data'},
 'date_detected': '2026-07-27',
 'date_publicly_disclosed': '2026-07-27',
 'description': 'Nuneaton and Bedworth Borough Council accidentally exposed '
                'the personal data of 2,900 voters in the Arbury ward during '
                'its annual electoral roll update. The breach occurred when an '
                'email sent to residents included a link to a spreadsheet '
                'containing names, email addresses, and personalized security '
                'codes that could allow unauthorized access to the council’s '
                'online voting system.',
 'impact': {'brand_reputation_impact': 'Yes',
            'data_compromised': 'Names, email addresses, and personalized '
                                'security codes',
            'identity_theft_risk': 'Potential',
            'systems_affected': 'Online voting system'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Administrative errors can lead to data breaches; need for '
                    'additional fail-safes',
 'post_incident_analysis': {'corrective_actions': 'Additional fail-safes to be '
                                                  'implemented',
                            'root_causes': 'Administrative error during annual '
                                           'electoral roll update'},
 'recommendations': 'Implement stricter data handling procedures and '
                    'fail-safes',
 'references': [{'source': 'Cyber Incident Description'}],
 'regulatory_compliance': {'regulatory_notifications': 'Reported to the '
                                                       'Information '
                                                       'Commissioner’s Office '
                                                       '(ICO)'},
 'response': {'communication_strategy': 'Public acknowledgment and apology',
              'containment_measures': 'Removed exposed data, notified affected '
                                      'individuals',
              'remediation_measures': 'Additional fail-safes to be '
                                      'implemented'},
 'title': 'Nuneaton and Bedworth Borough Council Leaks Personal Data of Nearly '
          '3,000 Voters',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.