Mumsnet reports data breach to ICO after problematic cloud move
Mumsnet admitted data breach fault after a botched upgrade shares its user's data


Mumsnet has reported itself to the Information Commissioner's Office (ICO) after a botched upgrade resulted in users accidentally logging into the accounts of others.
The parental forum believes that the breach was caused when moving its services to the cloud on Tuesday afternoon. The problem ran from 2pm Tuesday to 9am Thursday when the changes were reversed.
Almost 60,000 data breaches reported since May Student Loans Company hit by a million cyber attacks last year What is the Information Commissioner’s Office (ICO)? General Data Protection Regulation (GDPR)
The breach concerns logins where for three days users logging into their accounts at the same time as another user could have had their account info switched. A user alerted the company to the breach on Wednesday night saying that they were able to login and view another user's account.
Mumsnet said it is investigating its logs to determine the impact of the breach. Approximately 4,000 users were logged in during the three-day window, but Mumsnet doesn't know how many of those were actually breached. The company has only been made aware of 14 incidents so far and those individuals have been notified of the issue.
According to the site, logging into another user's account allowed them to see email addresses, account details, posting history and personal messages, but not passwords as they are encrypted.
"One must acknowledge that all software is imperfect and when software has bugs, when they're identified in productions systems they need to be patched or rolled back to a known good state quickly, and that's what has reportedly happened here," said Matt Walmsley, EMEA director at Vectra. "It's not clear to what degree pre-rollout testing occurred or if the "move to the cloud" was material in the incident."
No further incidents have been reported suggesting that it was the move to the cloud that caused the issues. Mumsnet founder Justine Roberts posted a blog post to apologise to users and notify them that it will report the breach to the ICO.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"You've every right to expect your Mumsnet account to be secure and private," she said. "We are working urgently to discover exactly how this breach happened and to learn and improve our processes. We will also keep you informed about what is happening. We will, of course, be reporting this incident to the information commissioner."
Mumsnet is not alone in this regard, as 2018 saw an unprecedented number of companies reporting data breaches, with almost 60,000 reported across Europe since GDPR came into force.
What's interesting about the Mumsnet incident is it's due to a fault during an upgrade to cloud services, highlighting the dangers of rushing digital transformations. To the company's credit, it acted swiftly and took steps to shut down the problem, notify its users and involving the regulator.
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
Putting small language models under the microscope
ITPro Podcast The benefits of small language models are undeniable – but they're no silver bullet
By Rory Bathgate
-
CyberOne appoints Microsoft’s Tracey Pretorius to its advisory board
News The threat intelligence leader will provide strategic guidance to CyberOne’s executive team
By Daniel Todd
-
ICO admits it's too slow dealing with complaints – so it's eying up automation to cut staff workloads
News The UK's data protection authority has apologized for being slow to respond to data protection complaints, saying it's been overwhelmed by increased workloads.
By Emma Woollacott
-
“Limited resources” scupper ICO probe into EasyJet breach
News The decision to drop the probe has been described as “deeply concerning” by security practitioners
By Ross Kelly
-
Surge in workplace monitoring prompts new ICO guidelines on employee privacy
News Detailed guidance on how to implement workplace monitoring could prevent data protection blunders
By Ross Kelly
-
TikTok could be hit with £27m fine for failing to protect children's privacy
News Social media firm issued with a notice from the ICO for potential violations of UK data protection laws
By Bobby Hellard
-
What is AdTech and why is it at the heart of a regulation storm?
In-depth The UK data regulator has come under heavy fire for consistently delaying much-needed action, privacy groups say
By Carly Page
-
ICO crackdown on AI recruitment part of three-year vision to save businesses £100 million
News ICO25 outlines a fresh approach that involves releasing learning materials, advice, and a new ICO-moderated discussion forum for businesses
By Connor Jones
-
Clearview AI fined £7.5m over improper use of UK data
News Australian facial recognition firm collected 20 billion images from the internet without consent in order to build its database
By Bobby Hellard
-
UK data watchdog cut IT spending by £1.2 million during pandemic
News The ICO’s IT budget has been slashed by around 23% since 2019
By Sabina Weston