Experian says it recovered and deleted data on 24 million South Africans after giving it to random 'marketing' person

Credit giant admits to handing over info after 'fraudulent data enquiry'


Credit reference agency Experian has suffered what it somewhat understatedly described as a "data breach" after the firm itself transferred the details of 24 million South Africans to one individual.

The credit reference agency admitted on its South Africa website that the "isolated incident" took place over what it said was a "fraudulent data enquiry".

24 million people's data was transferred to someone who contacted Experian and – as the company alleges – pretended to be a representative of a legitimate client. Included in that transfer were the details of 793,749 "business entities", according to the Morningstar financial newswire.

"Our investigations indicate that an individual in South Africa, purporting to represent a legitimate client, fraudulently requested services from Experian," the company said. "The services involved the release of information which is provided in the ordinary course of business or which is publicly available."

The Register is unaware of any legitimate public source of detailed data relating to more than 40 per cent of the population of an entire nation state, hoards of information leaked from other data grabs by more sophisticated hackers notwithstanding. South Africa has a population of around 56 million.

Experian said it had obtained an Anton Piller court order to seize and destroy the data it unwisely transferred to the individual, which is a type of search warrant in civil legal proceedings. In a statement the data broker said the order "resulted in the individual's hardware being impounded and the misappropriated data being secured and deleted".

It added: "We can confirm that no consumer credit or consumer financial information was obtained. Our investigations do not indicate that any misappropriated data has been used for fraudulent purposes. Our investigations also show that the suspect had intended to use the data to create marketing leads to offer insurance and credit-related services."

The South African Banking Risk Centre said in a statement that local financial institutions were trying to identify "which of their customers may have been exposed to the breach and to protect their personal information, even as the investigation unfolds".

The Register has asked Experian to comment.

Dave Barnett, head of edge security at infosec vendor Forcepoint, observed that "there is a ton of data within credit agencies" and said the allegedly illicit approach to Experian was unsurprising.

"The criminal Willie Sutton was asked once why he robbed banks, and his response was simple: Because that's where the money is," he sagely intoned to El Reg. "Data has value and there is a ton of data within credit agencies so it is no wonder Experian was targeted in this way. However, it is comforting that the attacker has been identified, steps are being taken to protect the victims, and the regulatory controls are working."

He concluded: "In this case, it really does feel like 'another day, another data breach'. Criminals will always gravitate towards the shiny objects and there is nothing brighter than personal and financial data."

In 2018 Experian's website was found to be exposing credit account unlock codes. Accounts can be frozen by their rightful holders to prevent criminals from using stolen credentials to apply for loans; exposing the PINs defeated that safeguard. The bug has since been fixed. ®


Other stories you might like

  • Will Lenovo ever think beyond hardware?
    Then again, why develop your own software à la HPE GreenLake when you can use someone else's?

    Analysis Lenovo fancies its TruScale anything-as-a-service (XaaS) platform as a more flexible competitor to HPE GreenLake or Dell Apex. Unlike its rivals, Lenovo doesn't believe it needs to mimic all aspects of the cloud to be successful.

    While subscription services are nothing new for Lenovo, the company only recently consolidated its offerings into a unified XaaS service called TruScale.

    On the surface TruScale ticks most of the XaaS boxes — cloud-like consumption model, subscription pricing — and it works just like you'd expect. Sign up for a certain amount of compute capacity and a short time later a rack full of pre-plumbed compute, storage, and network boxes are delivered to your place of choosing, whether that's a private datacenter, colo, or edge location.

    Continue reading
  • Intel is running rings around AMD and Arm at the edge
    What will it take to loosen the x86 giant's edge stranglehold?

    Analysis Supermicro launched a wave of edge appliances using Intel's newly refreshed Xeon-D processors last week. The launch itself was nothing to write home about, but a thought occurred: with all the hype surrounding the outer reaches of computing that we call the edge, you'd think there would be more competition from chipmakers in this arena.

    So where are all the AMD and Arm-based edge appliances?

    A glance through the catalogs of the major OEMs – Dell, HPE, Lenovo, Inspur, Supermicro – returned plenty of results for AMD servers, but few, if any, validated for edge deployments. In fact, Supermicro was the only one of the five vendors that even offered an AMD-based edge appliance – which used an ageing Epyc processor. Hardly a great showing from AMD. Meanwhile, just one appliance from Inspur used an Arm-based chip from Nvidia.

    Continue reading
  • NASA's Psyche mission: 2022 launch is off after software arrives late
    Launch window slides into 2023 or 2024 for asteroid-probing project

    Sadly for NASA's mission to take samples from the asteroid Psyche, software problems mean the spacecraft is going to miss its 2022 launch window.

    The US space agency made the announcement on Friday: "Due to the late delivery of the spacecraft's flight software and testing equipment, NASA does not have sufficient time to complete the testing needed ahead of its remaining launch period this year, which ends on October 11."

    While it appears the software and testbeds are now working, there just isn't enough time to get everything done before a SpaceX Falcon Heavy sends the spacecraft to study a metallic-rich asteroid of the same name.

    Continue reading
  • Rise in Taiwanese energy prices may hit global chip production
    National provider considering cost increase of 8%, which could be passed on to tech customers

    Taiwan's state-owned energy company is looking to raise prices for industrial users, a move likely to impact chipmakers such as TSMC, which may well have a knock-on effect on the semiconductor supply chain.

    According to Bloomberg, the Taiwan Power Company, which produces electricity for the island nation, has proposed increasing electricity costs by at least 8 percent for industrial users, the first increase in four years.

    The power company has itself been hit by the rising costs of fuel, including the imported coal and natural gas it uses to generate electricity. At the same time, the country is experiencing record demand for power because of increasing industrial requirements and because of high temperatures driving the use of air conditioning, as reported by the local Taipei Times.

    Continue reading
  • Tech companies ready public stances on Roe v. Wade
    Some providing out-of-state medical expenses, others spout general pro-choice statements

    Several US tech companies have taken a stance or issued statements promising healthcare-related support for employees following the Supreme Court's ruling to overturn Roe v Wade last Friday.

    A Supreme Court draft opinion that was leaked in February provided advanced warning of the legal eventuality, giving companies plenty of time to prepare official positions and related policies for employees.

    Without proper policies in place, tech companies could put themselves at risk of "brain drain" as employees become tempted to relocate to states where abortion access is readily available or to companies that better support potential needs as healthcare in the US is more often tied to an employer than not.

    Continue reading

Biting the hand that feeds IT © 1998–2022