Westminster Council website hacked

Hacked page screen shot

Hacked page screen shot

Today the Westminster Council website was hacked which demonstrates just how weak their site security is.  The council website now features the words Viagra on it’s WISH Organisation Details page. With the council responsible for handling large amounts of citizens personal information and credit card details we would have hoped the council would have taken website security more seriously than they have. This issue has become more important than ever, since Westminster Council became the only local authority to accept only credit cards as payment for parking in the borough.

Concerns have been raised previously regarding the safety of having a cashless parking scheme. Credit card information for the Pay-by-phone system is being handled by the Councils outsourced partner Verrus, who at present have been processing UK motorist’s credit card information in Canada.

When we asked Verrus about the security problems of forcing riders to stand out in the street with a credit card and mobile phone, they first said there were lots of occasions where people have to do that. But when we asked them to name one other situation where a customer was forced to stand outside in the dark reading out their credit card information into a mobile phone, they were stuck, and then they refused any further discussion on the matter.

After running the trial pay-by-phone scheme in Westminster, Verrus pointed out to the Council that they hold all the drivers details, and should they wish to use any other provider they would not be handing over any of the data. This would have forced all motorists to re-register for pay-by-phone, so not surprisingly Verrus have kept the contract in Westminster. (see also: Verrus and the golden pay-by-phone contract)

Angela Harvey ignored evidence

Angela Harvey ignored evidence

Verrus then went on to offer their services to other councils who were not in fact members of the Westminster led quango Partners in Parking (PiP). Not only offering their services but blatantly stating they would not need to tender, this is all highly illegal (see: Mike More gets slap).

The No To Bike Parking Taxes campaign group have tried to bring this to the attention of the Chairman of the Scrutiny Committee, Councillor Angela Harvey, but she ignored all the incontrovertible evidence presented to her. As has Head of Legal Peter Large and of course the Councils Chief Executive Mike More.

We maintain the whole story around Westminster, PiP and Verrus has the vile stink of a cover-up, and the Council and Verrus should be the last people you trust with your credit card information. We would not be surprised to hear next that customers data has been left on the 8:42 to Victoria soon.

We have been told that today’s hack has not been the first, with hackers claiming they have back door access at anytime, but they would not tell us us if that was to Verrus’s site or the Councils. Nutsville wonders what Verrus’s new owners PayPoint must be thinking, have they just bought a lemon with Verrus. Nutsville thought the Council had just taken to peddling Viagra to make up the losses it’s now claiming for the unpopular bike parking tax (see Lame duck tax).

Do you trust Westminster Council with your details?

Related links:

FOI asking about today’s hack

Saved page showing the hack

PayPoint completes acquisition of Verrus

===================================================


If you have a story you think needs a wider public audience please email us at:

news@nutsville.com

  • Share/Bookmark

1 Comment

1frogMarch 20th, 2010 at 9:22 pm

I’m glad i’ve never registered with the pay by phone system. I feel sorry for the thousands of poeple who’ve had to do it.

McMillanMarch 21st, 2010 at 10:39 am

It’s clear to me that Angela Harvey has other motives beyond the electorate of Westminster when she has stuck her head in the sand about this and refuses to comment, as do many of her colleagues regarding the scandal taking place at Westminster. She should have been suspended for failing to scrutinise this, instead she is complicit in the cover-up.

Perhaps Harvey has shares in Verrus?

Parson PeterMarch 21st, 2010 at 11:42 am

Maybe this is another super idea from Wastemonster, get the Viagra people to sponsor their web pages. I certainly see it as a bonus, not only can I go to the Westminster Website to carry out FOI requests but I can get my Erectile Dysfunction products at the same time! Forward thinking or what.

If Westminster are going to make my details available to people like this we can only expect better unsolicited services, leafets, cold calls and doorsteppers.

Maybe Westminster can do a deal with Boots and get Angela Harvey some cream for her Baboons Arse condition? What do you mean it’s lipstick, no-one would put it on that thick would they?

Richard HollyoakMarch 21st, 2010 at 11:52 am

Nothing like some forthright leadership from a “leadership expert” – Read her own copmany biography – no mention of her dismissive arrogance. She’s a Julia Middleton pastiche but with no Common Purpose ;)

http://topazleadership.com/angela.html

RogerMarch 21st, 2010 at 1:52 pm

Oh my god, I use the Pay By Phone system to pay for my car parking in the City of Westminster. I’m now extremely worried. Westminster City Council is obviously not at all interested in security, as long as they get their money. I would prefer to have the old fashioned parking meters back as I would rather the Albanian Mafia gets Westminster’s money than mine!

RazorMarch 21st, 2010 at 6:10 pm

This is why there should always be an option for people to be able to pay with good old cash.

I would never trust these people with my credit card details.

AnnoyedMarch 21st, 2010 at 7:51 pm

They don’t look like a flagship council to me!

BanditMarch 22nd, 2010 at 4:52 pm

So how many of you realised that by registering to Verrus, you are agreeing to your details being sent to Canada?
And, if you do not agree to this, you cannot use the pay-by-phone system.
Which, if you are a motorcyclist, means that you cannot park in Wesminster.

So what’s the choice: hand over your details to a foreign company, outside of UK jurisdiction, for God knows what purpose, or get fined by the same company.

As for Angela burying her head in the sand – can’t say I blame her. With a face like that, it’s the closest she’ll get to public service.

RitaMarch 22nd, 2010 at 5:06 pm

I never did trust Westminster City Council, but I trust them even less now (if that is possible).

Is there anything WCC can do competently?

Richard HollyoakMarch 22nd, 2010 at 5:09 pm

The Wednesday demos should be stepped up. If these morons wont see sense then we will have to make them at the very least pay at the ballot box.

In Angela’s own words:

“when it comes to policy, the electorate have the opportunity to comment once every 4 years”

How jolly decent of you Angela.

bratarerDecember 15th, 2010 at 3:25 am

” The council website now features the words Viagra on it’s WISH Organisation Details page. With the council responsible for handling large amounts of citizens personal information and credit card details we would have hoped the council would have taken website security more seriously than they have. This issue has become more important than ever, since Westminster Council became the only local authority to accept only credit cards as payment for parking in the borough.”
Are you sure that this is true?

Jenny MorganJuly 24th, 2011 at 9:54 am

Can we start a Midlands branch of Nutsville, please??

Leave a comment

Your comment

Spam Protection by WP-SpamFree