TransUnion staring down R10-million fine over data breach

Hanno Labuschagne

Journalist
Staff member
Joined
Sep 2, 2019
Messages
6,544
Reaction score
4,845
TransUnion staring down R10-million fine over data breach

Credit bureau TransUnion could be slapped with a R10-million fine after it suffered a data breach that compromised the personal information of millions of South Africans, the Information Regulator of South Africa has said.

The company confirmed on Thursday that a criminal third party had gained access to one of its servers by using an authorised client's credentials.

"We have received an extortion demand, and it will not be paid," TransUnion South Africa confirmed.
 
“Possible repercussions after all of the required processes and steps have been followed by the regulator, is a fine of up to R10 million or imprisonment of up to 10 years, or both a fine and such imprisonment,” the regulator stated.

That would apply if the regulator discovered any illegality or lack of proper safeguards for protecting the information.
A R10 million fine is probably close to what TransUnion SA makes in a day by peddling the personal information of South Africans, the fine is by no means a deterrent for this breach.

What would be more effective is fining TransUnion SA (and other credit unions in SA) for peddling every piece of personal information that they have hoarded.

Logistically, how would TransUnion SA be imprisoned (for up to 10 years)? Does it involve lots of razor wire being put up around TansUnion SA's HQ and having all services cut off, or do the directors of the company get to share a firepool with Zuma?
 
A R10 million fine is probably close to what TransUnion SA makes in a day by peddling the personal information of South Africans, the fine is by no means a deterrent for this breach.

What would be more effective is fining TransUnion SA (and other credit unions in SA) for peddling every piece of personal information that they have hoarded.

Logistically, how would TransUnion SA be imprisoned (for up to 10 years)? Does it involve lots of razor wire being put up around TansUnion SA's HQ and having all services cut off, or do the directors of the company get to share a firepool with Zuma?
You imprison the custodian of the data - the CIO.
 
"It also denied that the incident was a ransomware attack."

Oh i'm so happy they didn't attack your systems, they just stole all the data and held it ransom. I feel so much better now, thank you Transunion for confirming it was just a complete failure of security policies, not a little malware script encrypting your data.
 
A R10 million fine is probably close to what TransUnion SA makes in a day by peddling the personal information of South Africans, the fine is by no means a deterrent for this breach.

What would be more effective is fining TransUnion SA (and other credit unions in SA) for peddling every piece of personal information that they have hoarded.

Logistically, how would TransUnion SA be imprisoned (for up to 10 years)? Does it involve lots of razor wire being put up around TansUnion SA's HQ and having all services cut off, or do the directors of the company get to share a firepool with Zuma?

How do you suggest business see your history with credit? Scrap credit? They must just trust what you write down?
 
How do you suggest business see your history with credit? Scrap credit? They must just trust what you write down?
All of our personal information is stored in clear text by these buggers, and every time our personal information is compromised it is in clear text.

Banks should be exchanging credit data using one-way encryption, for example start with a query using a person's ID number: one-way encrypt the ID number such that you end up querying for a hash value, data associated with that hash value can similarly be stored and exchanged between entities in a way that never requires decryption.

If a database full of one-way encrypted data is compromised, the attacker can do nothing with the data even if the encryption algorithm is leaked/know (it's one-way encryption, as in cannot be decrypted).

TransUnion SA can be trusted to provide all of our personal information (in clear text):
1647763019339.png
 
Last edited:
Part of the law is notification to clients. I had a profile there to do a yearly check. I have not been contacted. I have also never specifically given them permission to distrube my personal data. From what I have read trans union have been criminally negligent
 
Last edited:
All of our personal information is stored in clear text by these buggers, and every time our personal information is compromised it is in clear text.

Banks should be exchanging credit data using one-way encryption, for example start with a query using a person's ID number: one-way encrypt the ID number such that you end up querying for a hash value, data associated with that hash value can similarly be stored and exchanged between entities in a way that never requires decryption.

If a database full of one-way encrypted data is compromised, the attacker can do nothing with the data even if the encryption algorithm is leaked/know (it's one-way encryption, as in cannot be decrypted).

TransUnion SA can be trusted to provide all of our personal information (in clear text):
ID numbers are not unique.



 
ID numbers are not unique.




They are unique if the issuing government is not incompetent pieces of sht.

What our government is doing is recycle ID numbers of people who died or in some cases havn't even died yet.

There is no reason to have to recycle ID numbers, someone need to inform our government that numbering systems can go higher if you choose to use higher numbering systems.
 
They are unique if the issuing government is not incompetent pieces of sht.

What our government is doing is recycle ID numbers of people who died or in some cases havn't even died yet.

There is no reason to have to recycle ID numbers, someone need to inform our government that numbering systems can go higher if you choose to use higher numbering systems.
Yes, which is why we customer numbers as a unique identifier in our databases.
Finding duplicate ID's is quite common when you have over 1 million clients.
 
ID numbers are not unique.



The issue here is not duplicate ID numbers, the issue is storing personal information in clear text in databases and then failing to properly/sufficiently secure access to the information.

Duplicate ID numbers are a separate issue that has nothing to do with negligence on the part of the custodians of personal information.

If you query for an ID number and you get more than one record, it is the same as querying for a one-way encrypted hash of an ID number and getting back more than one record. The difference is that an ID number stored in clear text is personal information that can be exploited, whereas a one-way encrypted hash value is not personal information that can be exploited.

Account numbers are also easy to one-way encrypt and store in a database as hash values, there is no reason why a credit union should have any person's account numbers at any financial institution (or credit provider) stored in a database in clear text.

Names and addresses are a bit more difficult because people make lots of mistakes when they capture data but you can replace some of the characters with something like a * character before sharing the data with a credit union. For example "Piet Pompies" could be changed to "P**t P*****s" when passing the data on to a credit union.

Other personal information and credit data can be de-personalised before sharing it with credit unions.

The credit unions monetise the personal information they collect for more than just credit checks. If credit unions are only provided with de-personalised data, they cannot abuse the data they are collecting.
 
Top
Sign up to the MyBroadband newsletter
X