- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Collapse
You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:
- You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
- You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
- If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.
Logging in...
Previously on "Employer holding masses of contractor data with no security - Advice?"
Collapse
-
I used to work for a large consultancy based out of NL and they did a similar thing for all staff.
-
I worked at a UK based big US bank. They kept all contractors details including rate on the general drive on an unprotected Excel spreadsheet in a folder call 'Contractors.'
Leave a comment:
-
Sounds to me like they have some form of security, where as you need to have an account within their network. So, open to the big wide world might not be the case.Originally posted by C0ntractor View PostI accessed the intranet portal from outside of the network using my credentials. The site was accessed lawfully but there are no security permissions set on any of the information/folder structure.
My contract with these guys is potentially coming to an end in a month or so...
However, if you can view everything internally, that should be raised with their internal systems team. It is also worth checking that your account isnt a member of some administration group to complete your job. But if you are asking on here about that, I would imagine your role doesn't work around permissions, or you would be already blocking access
Leave a comment:
-
Send it across to my mate Julian.Originally posted by C0ntractor View PostI accessed the intranet portal from outside of the network using my credentials. The site was accessed lawfully but there are no security permissions set on any of the information/folder structure.
My contract with these guys is potentially coming to an end in a month or so...
He's not home at the mo, but I've got his embassy address somewhere.
Leave a comment:
-
Seems clear he is on their network if he can access their intranet?
Regardless, still shocking that info is exposed for anyone on the intranet to sniff through.
Leave a comment:
-
I accessed the intranet portal from outside of the network using my credentials. The site was accessed lawfully but there are no security permissions set on any of the information/folder structure.
My contract with these guys is potentially coming to an end in a month or so...
Leave a comment:
-
The question I would ask is did you access their intranet from their network or an external network?
If the later then there is clearly a breach of access if the former then you may want to consult their code of connection for contractors as it may be your account has the correct permissions to view said records.
my 2 cents
Leave a comment:
-
I'd let them know first, and make sure they report it to the Information Commissioners Office - by law they have to report every data protection breach, and this sounds like a fairly serious one!
Leave a comment:
-
Contact them and ask them if they're aware that they've exposed the contents of their database to the entire world?
Or if you're not feeling helpful, contact a journalist.
Leave a comment:
-
Employer holding masses of contractor data with no security - Advice?
This is a bit of a weird one. I contract through a large well known service provider who deal with many contractors and clients in the UK. Today they sent me a newsletter with links to their intranet, which I've never seen before.
I decided to have a browse and out of curiosity I decided to search for myself to see what came up. To my horror ALL of my correspondence, including contracts, rates etc appeared in the search results and I was able to freely access and view these. Worse than that the site lets me browse directories and I can see (although I've not viewed) all the data for 100's of contractors, pretty much any info I require, rates, personal info, contracts etc.
I'm amazed that this data is so easily accessed and can be seen by anybody. Obviously I'm not happy that contract information can be accessed by anyone, I thought I'd first ask for some advice on here on how I should approach this.
Thoughts?Tags: None
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- Andrew Griffith MP says Tories would reform IR35 Oct 7 00:41
- New umbrella company JSL rules: a 2026 guide for contractors Oct 5 22:50
- Top 5 contractor compliance challenges, as 2025-26 nears Oct 3 08:53
- Joint and Several Liability ‘won’t retire HMRC's naughty list’ Oct 2 05:28
- What contractors can take from the Industria Umbrella Ltd case Sep 30 23:05
- Is ‘Open To Work’ on LinkedIn due an IR35 dropdown menu? Sep 30 05:57
- IR35: Control — updated for 2025-26 Sep 28 21:28
- Can a WhatsApp message really be a contract? Sep 25 20:17
- Can a WhatsApp message really be a contract? Sep 25 08:17
- ‘Subdued’ IT contractor jobs market took third tumble in a row in August Sep 25 08:07


Leave a comment: