SARS leaks over 30,000 e-mail addresses

This attachment was a text file with name beginning “File 8” and the extension “.CSV”.
What happened to file 13?
 
Very amateur mistake, and now someone has 20000 VALID email addresses for companies that are registered for SARS....

Way to go, morons.
 
Ask an employer. Once upon a time, not to long ago they made progress in public relations. In 2010/11 they fooked it all up again. I appointed an accountant just so that I don't have to communicate with the morons any more!:twisted:
 
That's a very bad attitude this Klingon has... assuming the worst of the innocent suckers who received this by threatening legal action repeatedly. It's their staff who need legal action taken against them for their negligence, if not the whole of SARS, for leaking information they are obliged to keep private... they can quit this nonsense about legal action being taken against us. I want to SMACK this Klingon tosser.
 
Aren't they also bound by the same confidentiality laws? They should take strong legal action against themselves.
 
Very amateur mistake, and now someone has 20000 VALID email addresses for companies that are registered for SARS....

Actually by my count they have around 35,000 valid addresses for employers. *Luckily* e-Filing logins are obfuscated - imagine if you logged in with your email address like with most other services.

That's a very bad attitude this Klingon has... assuming the worst of the innocent suckers who received this by threatening legal action repeatedly. It's their staff who need legal action taken against them for their negligence, if not the whole of SARS, for leaking information they are obliged to keep private... they can quit this nonsense about legal action being taken against us. I want to SMACK this Klingon tosser.

To be fair, I think they're really just trying to damage control with every tool in their box. They've asked people to please delete the addresses - but we all know that people don't just do something because you ask them nicely. So they've also given folks adequate warning about the legal action they could pursue if someone were to say, sell these addresses. Or add them to their own mailing databases.

How SARS will track down such folks I don't know, but at least no-one can say "but I didn't know" now.
 
To be fair, I think they're really just trying to damage control with every tool in their box. They've asked people to please delete the addresses - but we all know that people don't just do something because you ask them nicely. So they've also given folks adequate warning about the legal action they could pursue if someone were to say, sell these addresses. Or add them to their own mailing databases.

How SARS will track down such folks I don't know, but at least no-one can say "but I didn't know" now.
Sure, but what sort of action will be taken against/within SARS for this happening in the first place?
 
Section 4 (2A) No person shall in any manner publish or make known to any other person (not being an officer carrying out his duties under the control, direction or supervision of the Commissioner) the contents or tenor of any instruction or communication given or made by the Commissioner or any such officer in the performance of his or their duties under this Act for or concerning the examination or investigation of the affairs of any taxpayer or class of taxpayers or the fact that such instruction or communication has been given or made, or any information concerning the tax matters of a taxpayer or class of taxpayers: Provided that the provisions of this subsection shall not be construed--

i) as preventing any taxpayer or his representative who is or may be affected by any such examination, investigation or furnishing of information from publishing or making known information concerning his own tax matters; or

ii) subject to the provisions of subsection (1). as in any way limiting the duties powers of the Commissioner or any such officer; or

iii) as preventing any person from publishing or making known anything which has been published or made known by the taxpayer or his representative as contemplated in paragraph (i) or by the Commissioner or any such officer in the exercise of his duties or powers.

So how does this email fall under "for or concerning the examination or investigation of the affairs of any taxpayer" part exactly?
 
To be fair, I think they're really just trying to damage control with every tool in their box. They've asked people to please delete the addresses - but we all know that people don't just do something because you ask them nicely. So they've also given folks adequate warning about the legal action they could pursue if someone were to say, sell these addresses. Or add them to their own mailing databases.

How SARS will track down such folks I don't know, but at least no-one can say "but I didn't know" now.

The only person who we know to have actually committed anything resembling a crime is in fact SARS itself. Let's not have our attention deflected from that, even if Klingon would like us to feel that rather than being victims of this privacy violation, we are in fact the potential criminals.
 
“SARS will not hesitate to take the strongest legal action against anyone found to have saved, used or distributed the list of e-mail addresses,” the mail said, citing section 4(2A) of the Income Tax Act.

So like, they'll sue themselves? :)
 
I think they should give every person in the list tax off for a year. :) I'd be willing to sit with the spam etc. if I don't have to pay taxes for a year!
 
Sure, but what sort of action will be taken against/within SARS for this happening in the first place?

As stated in the article, they've suspended some folks pending an investigation. Based on my basic working knowledge of labour procedures the outcome of the investigation will determine whether the people at fault get written warnings, final warnings, or fired.

To be honest I'm not that interested in seeing people get fired - I'd much prefer to know that stuff like this won't happen in future.

On a side note: Does anyone know of a bulk mailer system that attaches the list of email addresses it is sending to as a CSV? Or do you think it's more likely that someone who didn't know how the system works attached the CSV to the mail instead of importing the addresses from the file?
 
I think they should give every person in the list tax off for a year. :) I'd be willing to sit with the spam etc. if I don't have to pay taxes for a year!

Heh. Ad-supported tax rebates.
 
On a side note: Does anyone know of a bulk mailer system that attaches the list of email addresses it is sending to as a CSV? Or do you think it's more likely that someone who didn't know how the system works attached the CSV to the mail instead of importing the addresses from the file?

I suspect their mailer has an input for the "target addresses" CSV file and another input for any attachments. The person then went and put the CSV file in both inputs. Sort of like forgetting to attach the file you said you were going to except worse.
 
Top
Sign up to the MyBroadband newsletter
X