Afrihost client data leaked: company apologises and explains

Pretty sure quite a few people saw those details, there was a link to it on this forum and some other forums, this was all about ten days ago.

No issue with that if it was only names and addresses. You can in any event find this type of information freely over the internet. Just go to your local city council and do a valuation roll lookup. Go to the white pages and enter a surname and town. You will get names and addresses and there are no law preventing this information from being displayed.
 
Pretty sure quite a few people saw those details, there was a link to it on this forum and some other forums, this was all about ten days ago.

I never saw that link - which I regret now so we could have resolved this much earlier. If that's the case then it may be some comfort that nothing significant has been done with that information as yet :(
 
I never saw that link - which I regret now so we could have resolved this much earlier. If that's the case then it may be some comfort that nothing significant has been done with that information as yet :(

Initially no one knew who the accounts were associated with and were pointing fingers at telkom. See here : http://mybroadband.co.za/vb/showthread.php/544781-TelkomZA?p=11612079&viewfull=1#post11612079

No issue with that if it was only names and addresses. You can in any event find this type of information freely over the internet. Just go to your local city council and do a valuation roll lookup. Go to the white pages and enter a surname and town. You will get names and addresses and there are no law preventing this information from being displayed.

I wasnt trying to say its right or wrong, was just providing more information.
 
Has anybody read POPI? Would this have been in contravention of the bill if it wasn't for the 1 year period that is given for people to comply?
 
Well, this happened. There is no turning back.

At least the company had the honesty of admitting it and informing people that they have already taken remedial actions to prevent further exposure. It is better dealing with such company than one who refuse to answer or tries to hide it.

Name and address information is indeed important and is valuable to large syndicates. This information can be used to plan robberies or simple burglaries. Knowing where the list originates from some people can already make some deductions as to the type of income the people on the list earns.

However, this information can also be obtained from telephone directories, from municipal valuation rolls or even from the official online white pages.

So, I agree, people have nothing to worry about if it was only names and addresses that were leaked. There should be no consequences at all for Afrihost, whatsoever.

We're glad to hear that other agree that the impact will not be significant if any, but at the end of the day we still have to account for our breach of our clients trust. We definitely know never to do something like this again and we'll be double and triple cautious to ensure that privacy is absolutely paramount.
 
What steps to protect client information were in place before this breach? What corrective actions have you now taken to prevent a breach of this nature going forward?

Our client data is stored on encrypted data base and is always hidden. We also recently upgraded our systems to no longer send ClientZone passwords in plain text. As far as day to day security - we believe this is still rock-solid.

This was a particular internal exercise and the information was never designed for any purpose other that generating internal maps of geographical clusters of our clients base - to look at what further services and added value we could bring to clients.
 
Has anybody read POPI? Would this have been in contravention of the bill if it wasn't for the 1 year period that is given for people to comply?

POPI is more focussed on misuse of private information for marketing purposes or "selling lists" to marketers. While the Act provides for the safeguarding and best practice for securing information and private records - I don't this particular issue would fall under malicious or intentional misuse of client data.

Either way, we still accept full responsibility and we are committed to ensuring that something like this will NEVER happen again :(
 
Has anybody read POPI? Would this have been in contravention of the bill if it wasn't for the 1 year period that is given for people to comply?

Yes, in terms of the new POPI act this would have been a classic example. They would not have ended up in court, but the regulator could have fined the company up to R1m per record that leaked if they found the company was negligent with storing and managing the data.
 
POPI is more focussed on misuse of private information for marketing purposes or "selling lists" to marketers. While the Act provides for the safeguarding and best practice for securing information and private records - I don't this particular issue would fall under malicious or intentional misuse of client data.

Either way, we still accept full responsibility and we are committed to ensuring that something like this will NEVER happen again :(

POPI is about much more than just marketing and specifies what personal data might be held, for how long, for what purposes and in what format, as well as safeguards that are to be put in place with that data.
 
You can't compare the disclosure of name and address vs the disclosure of invoices, property values, banking details or other financial information etc. Not the same type of data and sensitivity. What was on Afrihost's list of information you could look up in a phone book or find in the trash of thrown away mail.

Only convenient thing is that people now know where Gian lives but even this you could have figured out by other means ;-)


I am an Afrihost client but they dont manage my line.

BTW you mention the leak of property values as more severe?
Of course property values are indeed public as is the address and the Deed Holders name
If you own your house (and not via a Trust) there is a lot of info avail)


At the end of the day I would have been peeved if I had been exposed
However the damage seems low...
They apologised
They have hopefully learned their lesson
 
What steps to protect client information were in place before this breach? What corrective actions have you now taken to prevent a breach of this nature going forward?

I think that it would not necessarily apply. There was no intent to use the information for any other purpose other than internal use. Believe me, something like this will not be happening again :(
 
Aside from the breach of privacy, the publication of the list has also given Afrihost's competitors insight as to the extent of Afrihost's bundled DSL subscriber base, along with a shopping list of potential customers to be targeted/persuaded to migrate away.

Definitely a black eye for Afrihost... and I am still waiting for a formal notification of the information breach - would have liked to be informed first before finding this out on a public forum.
 
No issue with that if it was only names and addresses. You can in any event find this type of information freely over the internet. Just go to your local city council and do a valuation roll lookup. Go to the white pages and enter a surname and town. You will get names and addresses and there are no law preventing this information from being displayed.

Either way, we regret that the info was shared in any way through us, but we're grateful that nothing very compromising was shared and we believe that exposure was limited :(
 
ah well, so since you say it is people with managed lines from afrihost, I know I am on the list. Perhaps some guys from anonymous will come have a beer with me now...been trying to join those guys for ages :D...

To the NSA reading this post, I am only kidding kay...
 
POPI is about much more than just marketing and specifies what personal data might be held, for how long, for what purposes and in what format, as well as safeguards that are to be put in place with that data.

True, but it would be unreasonable to assume that companies would not use information internally for management and internal planning purposes. That was the only intent here, and the leak was an unfortunate mistake.

Many companies will continue to use information like this for the same purposes after POPI comes into effect.
 
Top
Sign up to the MyBroadband newsletter
X