ABC Security Incident - March 2022

Background to the Incident On 1 March 2022 it was discovered that a security breach occurred on the information technology environment of ABC. In the subsequent investigation it was discovered that an unidentified individual or group gained access to the environment and executed Ransomware that encrypted the information.

Due to the adherence to strict disaster recovery protocols ABC was able to restore the data and recover the environment to limit any interruption of services and damage to data.

Unfortunately, the investigation found indication that supported that there are reasonable grounds to believe that the personal information of certain data subject, who’s information was stored in the IT infrastructure of ABC was accessed or acquired by any unauthorised person.

ABC has taken the following remedial action:

  • All passwords and user account within the organisation was reset
  • Two factor authorisation was activated
  • All software was updated
  • All patch management was updated
  • Whitelisting of IP addresses enforced

All data subjects who’s information was held by ABC is hereby notified in terms of Section 22 of the Protection of Personal Information Act, Act 4 of 2013 of the unauthorized access or acquisition of their personal data.

In terms of Section 23 of the Protection of Personal Information Act, Act 19 of 2013 (POPIA) you as a data subject have the right to request a Responsible Party to confirm if it holds your personal information.

The information that was accessed or acquired include information such as:

  1. information relating to the race, gender, sex, pregnancy, marital status, national, ethnic or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language and birth of the data subject;
  2. information relating to the education or the medical, financial, criminal or employment history of the data subject;
  3. any identifying number, symbol, e-mail address, physical address, telephone number, location information, online identifier or other particular assignment to the data subject;
  4. the biometric information of the data subject;
  5. the personal opinions, views or preferences of the data subject;
  6. correspondence sent by the person that is implicitly or explicitly of a private or confidential nature or further correspondence that would reveal the contents of the original correspondence;
  7. the views or opinions of another individual about the data subject; and
  8. the name of the person if it appears with other personal information relating to the data subject or if the disclosure of the name itself would reveal information about the data subject;

Personal information of data subjects is often sought by perpetrators to execute such crimes as:

  • Identity Theft
  • Fraud
  • Impersonations
  • Phishing attacks

It is recommended that all data subjects follow the following precautionary measures:

  • Change your passwords as soon as possible and it is advisable to regularly change all passwords and security questions
  • Don’t use the same password everywhere
  • Activate two factor authentication where possible on all your accounts
  • Monitor your credit rating
  • Watch your accounts, check your credit reports
  • Consider identity theft protection services
  • Freeze your credit if required
  • Do not disclose personal information such as passwords and PINs when asked to do so by anyone
  • Verify all requests for personal information and only provide it when there is a legitimate reason to do so.