Cyber Incident Victim: Sussex Police
Date:
Dec 2014
Location:
United Kingdom
Summary
Sussex Police investigated security breaches targeting a contained section of their external website during a holiday period, with three potentially linked incidents compromising email addresses of officers and personal email addresses of some public users who interacted with the site. Approximately 270 affected individuals were contacted to receive security guidance, particularly regarding password management for the community messaging service, though operational systems and public services remained unaffected. The force confirmed the breaches were isolated from crime investigation systems and implemented measures to prevent further compromise while pursuing an active investigation to identify those responsible.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Sussex Police experienced multiple security breaches targeting a contained section of their external website during the Christmas period of 2014. Three separate incidents were identified, with investigators noting the possibility of a connection between them. The breaches resulted in unauthorized access to email addresses belonging to police officers and personal email addresses of members of the public who had interacted with the website's services. Amaraghosha Carter, joint head of IT for Surrey and Sussex police forces, confirmed the force initiated a full investigation to determine the origin of the breaches and assess their full impact. Communications staff proactively contacted approximately 270 potentially affected individuals, focusing on providing security guidance related to password management for the community messaging service. The compromised website operated independently from core police systems used for criminal investigations, with no evidence of operational disruption to response capabilities or other IT, web, or telephony infrastructure.

Authorities emphasized that public services remained unaffected throughout the incident. Immediate containment measures were implemented to prevent further website compromise while forensic work continued to identify those responsible. Investigators concurrently conducted system-wide reviews to reinforce IT security resilience across all force systems. Sussex Police publicly requested information related to the breaches and directed concerned citizens to contact them via phone or email using a specific reference number (serial 1483 of 23/12). The force maintained transparency regarding the breach scope while assuring stakeholders that critical law enforcement functions remained insulated from the website security failure. No operational service degradation or secondary system compromises were reported following the initial containment actions.
