Information Regulator slaps TransUnion with enforcement notice

Jan

Who's the Boss?
Staff member
Joined
May 24, 2010
Messages
14,887
Reaction score
13,574
Location
The Rabbit Hole
Major credit bureau slapped with enforcement notice for data breach in South Africa

The Information Regulator has slapped credit bureau TransUnion with an enforcement notice following a data breach on 18 March 2022.

N4ugthySecTU, the group that claimed responsibility for the attack, alleged that they exfiltrated 4TB of data from one of TransUnion’s databases, including the records of 54 million South Africans.
 
Toothless. Fine them millions and then it won't happen again. They won't want another fine so they'll go far in excess of what the regulator is demanding. Other companies will take heed and do the same. Win win.
 
They should boost TransUnion. These credit bureaus harvest all your personal details and then you can buy it if youre a company at R15 a record. Obviously cheaper to just hack it and steal it. But I have seen how much details they can store on you and it goes back very long. For me it was since I opened my first bank account when I was 12. A lawyer friend demanded that they extract all my data, and it went back over 30 years of records. Where I stayed, what all my past phone numbers was, etc. Pages and pages of records etc.
 
They should boost TransUnion. These credit bureaus harvest all your personal details and then you can buy it if youre a company at R15 a record. Obviously cheaper to just hack it and steal it. But I have seen how much details they can store on you and it goes back very long. For me it was since I opened my first bank account when I was 12. A lawyer friend demanded that they extract all my data, and it went back over 30 years of records. Where I stayed, what all my past phone numbers was, etc. Pages and pages of records etc.
Well, that is exactly the kind of info one wants when granting credit to someone. As much as possible.
I make use of their services daily. 1000's of enquiries every month. The more info the better.
 
Well, that is exactly the kind of info one wants when granting credit to someone. As much as possible.
I make use of their services daily. 1000's of enquiries every month. The more info the better.
A lot of eggs in one basket. Bank level security should have been enforced on these type of companies. Just shows how little our personal data is valued. This is a slap on the wrist. Until the next attack - sadly this won’t end.
 
At this point we may as well cut out the middle men and just publically sell our own data online and be done with the pointless and futile privacy laws.

MDAAS - My Data As A Service
 
Actually scrap that idea. If anything this pretend "private data" has only given rise to a system that attached financial incentive to data.

Scrap the privacy laws and remove the incentive for the black market trade of the data since it is not longer a "precious commodity". It also removes the parasitic data processing companies. If one removes the value of the data it will limit profiteering (both legal and illegal)

At this point my data has been leaked so many times that I may as well have published it myself for all to see. Besides there is not much I worry about with it in the first place.

Any system that relies on absolutely everyone doing the right thing and ultimately boils down to the lowest common denominator is doomed to fail.

If anything all the privacy laws have done is create a black market for data, an additional form of taxation for governments and a lot of pointless noise about breaches.
 
A slap on the wrist indeed for TransUnion. Meanwhile, with our personal contact details out in 'the wild' / dark web, our e-mail inbox is spammed regularly. Thank goodness for mail filtering systems, but some nonsense still manages to get through.‍♀️ Any company or government institution (the worst culprits!) that does not guard our information 100%, or sells it to marketing companies, should be fined heavily and this money used to compensation those who had their details stolen.
 
Fines should be fixed cost.

R10 per personal record. Times 1 multiple for each field per record.

Name and surname = 10 x 2 = R20 per recoord
Name surname and ID number = 5 x 3 = R30 per record.
Allowing for an average of 20 fields like the credit agencies likely have = R 200 per record.

R10.8 billion fine sounds about right for this level of incompetence. It should be a financial death penalty at this level.
 
Top
Sign up to the MyBroadband newsletter
X