UK National Property Register Site Exposed 28 Million Records: Researcher
Immobilise, the website of the United Kingdom's National Property Register, was plagued until recently by a privacy flaw that could have been exploited to harvest information on millions of registered users, a researcher revealed on Monday.
Context & Ripple Effects
Immobilise sits at an awkward intersection: a government-backed register where citizens voluntarily hand over ownership details of their valuables, run on the assumption that registration is private. A researcher's disclosure shows that assumption failed at scale — 28 million records reachable through a privacy flaw until recently patched.
The exposure fits a documented run of UK organizations leaving personal data behind weak access controls: Virgin Media left a marketing database of roughly 900K customers unsecured for months, researchers found an ad agency exposing 150K+ records from user-filled forms, and the Electoral Commission later disclosed a hack whose full scope was never conclusively determined. Immobilise differs mainly in that the data was volunteered by citizens for safekeeping, which raises the trust stakes.
First-order effects
- Registered Immobilise users — up to 28 million of them — had their entries exposed to anyone who exploited the flaw, directly undermining the service's promise that registering property protects rather than exposes the owner.
- The operator must now respond as a breached custodian: fix the flaw, assess how long it was exploitable, and decide whether and how to notify users who signed up precisely to safeguard their information.
Second-order effects
- Other UK holders of citizen-supplied registries face pressure to audit their own permission boundaries, since researchers have demonstrated a repeatable playbook: probe a public-facing register, harvest what misconfiguration leaks.
- Consumer willingness to volunteer data to national registers takes a hit, forcing such services to justify their security posture rather than assume participation — the same dynamic Privacy International targeted when filing complaints against major data brokers.
Third-order effects
- If the pattern holds, UK data protection shifts from trusting institutional custodians to external verification — researcher discovery, breach databases like Have I Been Pwned, and regulator complaints become the real enforcement layer for organizations that hold data citizens cannot opt out of entrusting to them.
The trend: Organizations holding voluntarily submitted personal data are increasingly exposed by basic access-control failures discovered by outside researchers rather than by internal governance.