Sunderland City Council
| Primary URL | Location | Industry | sunderland[.]gov[.]uk |
Country
United Kingdom
|
Government - Local
|
|---|
Profile
Sunderland City Council, also known as City of Sunderland Council or Sunderland Council, is a local government authority based in the United Kingdom. Its headquarters are located in the United Kingdom, serving the metropolitan area of Sunderland. As a municipal body, the council delivers a range of public services to residents, businesses, and visitors within its jurisdiction. These services include, but are not limited to, library services, which maintain a customer database for registered users. The council operates under the framework of UK local government legislation and is accountable to the local electorate. Its core mandate is to support community wellbeing through the provision of essential amenities and administrative functions. The organisation is recognised by its several aliases in official communications and public records.
In November 2018, the council experienced a significant cyber incident characterised by a surge of approximately 400,000 spam emails, accompanied by phishing, spoofing, and at least one distributed denial‑of‑service attack over a week‑long period. During the same incident, attackers conducted a password spray effort that locked numerous accounts by repeatedly trying common credentials. An internal review undertaken after the event identified prior deficiencies in the council’s technology standards and compliance, which had been rated inadequate in a recent audit. In response, the council outlined a programme to improve its security posture, including plans to migrate systems to Windows 10 and to enforce mandatory default password changes. A separate cyber attack in May 2019 targeted the library services customer database, resulting in unauthorised access to personal information for about 45 of roughly 145,000 user accounts. The compromised data included names, dates of birth, and telephone numbers, prompting the council to launch an investigation and advise affected individuals to remain vigilant. Both incidents highlighted the need for ongoing cybersecurity improvements while acknowledging that absolute protection cannot be guaranteed.
