TransUnion reveals details about massive data breach

Hanno Labuschagne

Journalist
Staff member
Joined
Sep 2, 2019
Messages
6,543
Reaction score
4,845
TransUnion reveals details about massive data breach

Credit bureau TransUnion has revealed more details about the extent of a recent data breach that compromised the personal information of millions of South Africans on one of its databases.

TransUnion confirmed that at least 3 million customers were impacted, including South African consumers and non-South African residents who have transacted in the country.

Another 6 million ID numbers were exposed that had no personal information linked.
 
It's time that these credit agencies get nailed with hefty fines. There needs to be a cost linked per record breached. I think about R100 per record would be reasonable, along with the banks and financial institutions that clearly did not fulfil their POPIA obligations of doing proper due diligence before they just blindly share our data with them.
 
So why do we have the POPIA act when data breaches are happening more frequently.
 
It's time that these credit agencies get nailed with hefty fines. There needs to be a cost linked per record breached. I think about R100 per record would be reasonable, along with the banks and financial institutions that clearly did not fulfil their POPIA obligations of doing proper due diligence before they just blindly share our data with them.
Far too little. If it results in identity theft the damage is way higher than r100 to fix the issue or the loan that is taken out.
 
It's time that these credit agencies get nailed with hefty fines. There needs to be a cost linked per record breached. I think about R100 per record would be reasonable, along with the banks and financial institutions that clearly did not fulfil their POPIA obligations of doing proper due diligence before they just blindly share our data with them.
R100 per record is not nearly enough, I suggest R100 per database field not excluding duplicates across database tables (that has the added benefit of getting them to sort out bad database design).

“Each data subject may have a combination of different fields impacted, depending on what data was available,” TransUnion added.
That right there tells me that TransUnion is spin-doctoring and trying to downplay the severity of the breach and that TransUnion hasn't got a clue yet as to exactly what data was involved in the breach.

It is reasonable to assume that TransUnion is being extremely disingenuous, just like Experian was and still is.

Of course TransUnion should not pay any ransom, no one (companies included) should ever pay ransoms because there is never any guarantee that the ransom will stave off the release of data (or in the case of ransomware encrypted data, that the encrypted data would be decrypted and recovered).
 
I think it is time for a class action lawsuit. This is just not acceptable. We don't have a choice to whether they keep our information or not.

This has a huge personal security impact as we can't know what it is used for.
 
It's time that these credit agencies get nailed with hefty fines. There needs to be a cost linked per record breached. I think about R100 per record would be reasonable, along with the banks and financial institutions that clearly did not fulfil their POPIA obligations of doing proper due diligence before they just blindly share our data with them.
+1
According to my calculation the regulator should fine Transunion at least R217-million ($15-million).
 
Experian - nothing happened to them.
TransUnion - nothing will happen to them.

Time for a class action lawsuit.

I emailed the regulator & Experian about the Experian loss - nothing happened - except some pretty feeble excuses.
 
Experian - nothing happened to them.
TransUnion - nothing will happen to them.

Time for a class action lawsuit.

I emailed the regulator & Experian about the Experian loss - nothing happened - except some pretty feeble excuses.

Where are the entrepreneurial lawyers? :unsure: :ROFL:
 
So is it 54 million or 3 million?
3 million is TransUnion's lame attempt at spin-doctoring.

Until TransUnion is able to definitively prove otherwise, everyone should assume that every scrap of data TransUnion had, was compromised in this breach.

Anytime any company has a data breach, the onus should be on the company to prove that the breach was anything less than all the data they held, and the public should assume that to be the case (including investors buying and more importantly selling shares on stock exchanges).

Data regulators should impose maximum possible fines for each breach, it would then be up to the company in question to definitively prove that less than the maximum data was compromised and negotiate down from the maximum fine. The point of this would be to act as a deterrent to force companies to take security seriously.

Listed companies that fail to properly secure data should experience the burn of major selloffs, call it a vote of no confidence by major traders/investors.
 
Its time we should launch a class action against Transunion. It openly sells our information to 3rd parties without our permission. My wife discovered at her one company people could pay R15 for anyone's details if they had their ID number and could pull a full credit report. When we sign up at the banks we dont approve of this yet they forward it irrespective. In many countries there arent credit bureaus and its all individual lender run. But in SA they use our info as they see fit and sell it on. Transunion is the biggest transgressor with this and should be adequately punished.
 
There is a fine of R10 million or 10 years in prison. All Transunion employees even theyr management involved to this should be sent to jail for 10 years.

ERA caused a similar incident. They were actually pulling records from Transunion and putting it in their own db. Which got leaked. Was the biggest leak. They didnt even get a slap on the wrist.


Its time transunion allows a page where we can see using our details what was leaked. And then can file a claim against them.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X