Data breach: 24 million South Africans’ data exposed

As many as 24 million South Africans and almost 800 000 businesses may have been affected by a major data breach to hit credit bureau Experian.

A fraudster posing as a client of the credit bureau gained access to the details via social engineering, rather than hacking. The attacker’s success shows how easy it is for cyber criminals to execute unlawful events, despite constant reminders from cyber security providers to put comprehensive measures in place to minimise the risk of attack.

South African banks are in the process of working with Experian to determine which of their clients’ data has been exposed. By law banks have to disclose details of customers who have credit with them to three credit bureaus, including Experian.

In response to the incident, Experian has issued a statement saying its investigations indicate the misappropriated data hasn’t been used for fraudulent purposes. Also, no consumer credit or consumer financial information such as banking details were obtained.

However, a breach of basic personal information such as ID numbers, phone numbers and addresses can still lead to the possibility of impersonation. The South African Banking Risk Centre warns that attackers can use personal information to trick you into disclosing your confidential banking details, so extra vigilance is required when opening emails, and responding to them.

What does it say about the state of data protection in SA?

On hearing this news South Africans may well feel violated. If you’ve borrowed money or entered into any formal financial transaction, Experian is likely to hold information about you such as your personal details and financial history.

Experian also holds rental information, all the addresses you may be, or have been, linked to, electoral role information, credit details and details of public orders. We can request this data about ourselves, but do we have the certainty that it’s being kept securely?

The other question is: if large corporate enterprises don’t have state-of-the-art cyber security measures in place then how are small businesses faring in terms of their efforts towards data protection?

No business is too small to face a breach – each one needs cyber protection to protect itself against a disaster of this kind, not only in the interests of upholding its reputation, but in safeguarding its systems and protecting the valuable personal information of the people it holds.

Here at IronTree we eagerly await the rollout of the Protection of Personal Information Act (POPIA), South Africa’s equivalent of the EU’s GDPR, which will see each one of us empowered to control the destiny of our personal data.

IronTree is hard at work, working with the appropriate partners to ensure education and protection happens for businesses and individuals, so watch this space.

In the meantime, talk to us, and let’s tailor a data protection plan for your business.

Talk to us about POPIA

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

Does your business send bulk emails?

Learn all you need to know about Google & Yahoo’s new requirements for bulk email senders.

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

"*" indicates required fields

Hidden

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

This field is for validation purposes and should be left unchanged.

"*" indicates required fields

Hidden

Training

We also offer certified training packages The training will cover POPIA in general. We have two options available. Once off costs. Employee Awareness Training - R490 per candidate Senior Employees Awareness Training - R650 per candidate All prices exclude VAT

Company Structure

Are you part of a group structure?*
IronTree is committed to protecting and respecting your privacy, and we'll only use your personal information to administer your account and to provide the products and services you requested. From time to time, we'd like to contact you about our products and services, as well as any other content that may be of interest to you. If you consent us contacting you for this purpose please tick the checkbox below*

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

"*" indicates required fields

Hidden

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

Give us a call:

+27 87 943 2278

Send us a WhatsApp:

+27 66 372 4061

Drop us an email:

After hours support:

+27 72 595 1066

After hours hosting support:

+27 76 102 9813

Log a support request

The reseller zone is currently out getting a facelift as we look to integrate it with our backup platform, as it stands you can overview your clients on our new backup console. If you don't know what console that is, please reach out to us.

"*" indicates required fields

Hidden

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

This field is for validation purposes and should be left unchanged.
One of our team members will be happy to help answer any questions you have!
Just click the chat icon in the right-hand corner.