Select Page

Incident: Finsure confirms ‘cyber incident’ impacting customers and brokers | TheAdviser

Incident: Finsure confirms ‘cyber incident’ impacting customers and brokers | TheAdviser

Australian Finance Services Privacy Breach, 27 November 2024

Australian mortgage broker Finsure confirms ‘cyber incident’ impacting customers and brokers.

Finsure has confirmed that the marketing data of a number of its brokers and customers was impacted as a result of breach of their third-party provider Activepipe.

Source: Finsure confirms ‘cyber incident’ impacting customers and brokers | TheAdviser

View more incidents relating to the Banking and Finance sector and incidents resulting from Third-Party Risk Management.

Summary:

Finsure, an Australian mortgage broking group, has confirmed a cyber incident that impacted the marketing data of nearly 300,000 brokers and customers. The data breach was linked to a third-party service provider, ActivePipe, and included names, phone numbers, and physical addresses. No financial data or passwords were compromised.

Finsure said it has since worked with the third-party provider – presumably ActivePipe – and the issue has been resolved.

Statements:

  • Finsure: “We have worked with the third-party provider and cyber security experts to review the data on the impacted system. There is no evidence of misuse or publication of any individual’s personal information.”
    ActivePipe: “At no point was the ActivePipe platform breached. We are investigating our legal options as we consider the communication misleading and damaging to our company’s reputation.”
    Impact: The incident has raised concerns within the finance industry, highlighting the need for robust cyber security measures. Finsure has reassured customers that no sensitive financial information was exposed.
    Related Incidents:
    Previous breaches in the finance industry, including Firstmac and Latitude, have prompted increased education and support for brokers to enhance cyber security protocols.
    Conclusion: Finsure remains committed to protecting personal information and has taken steps to address the incident. The company apologizes for any concern caused and continues to work on improving its security measures.

Conclusion:
This is a lower-level breach of basic PII information, though adding the physical address for an individual to the big pool of dark web data is not good. Once again, Third-Party Risk Management is in play, and I wonder if their Information Asset Register had ActivePipe as a holder of PII information.

Related Incidents:
Previous breaches in the finance industry, including Firstmac and Latitude, have prompted increased education and support for brokers to enhance cyber security protocols.

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

Experts sound alarm on rise of fake digital IDs | 9 News Australia

There's a warning tonight about a rise in fake digital IDs being sold to teenagers. Cyber safety experts say it's putting vulnerable Victorians at risk of having their identities stolen. [...]

Aussie government announces cyber security labelling scheme for smart devices

The federal government has launched a pilot scheme that will allow Australians to compare the cyber security of smart devices before buying them. • … [...]

ACMA fines Telstra for SIM swapping prevention misses

Key points ACMA has fined Telstra $277,000 for failing to use required identity authentication processes to prevent SIM swapping fraud. • The fraud … [...]

The Next Wave of Australian Privacy Reform: Key Pr... | Clayton Utz

Modernised Definitions: Casting a Wider Net The Exposure Draft Bill would amend and clarify some of the foundational definitions in the Privacy Act … [...]

Labor’s privacy reforms are the boldest we’ve had in years. But there’s a hole to plug

Shifting the emphasis from individuals upholding privacy standards to harmful and invasive business practices is the right move. But an existing … [...]

In brief: cyberthreat detection and reporting in Australia

Threat detection and reporting Internal policies and procedures What policies or procedures must organisations have in place to protect data or … [...]

Telstra sowed seeds for its July mobile outage in 2020. Six years on they sprouted.

When Telstra engineers embarked on a simple server chassis replacement exercise in 2020, they could barely have contemplated the complex chain of … [...]

Exclusive: NSW Health denies Medusalocker data breach claims

Ransomware actor claims hack of government department, but evidence suggests no malicious activity has occurred… But patient data from multiple … [...]

NT gov starts path to digital driver's licence

Key points The Northern Territory government plans to offer digital driver's licences built to internationally recognised standards by the end of the … [...]

Privacy Act overhaul to tighten 72-hour breach reporting deadline

Key points Draft legislation would give Australian organisations 72 hours to notify the Information Commissioner of an eligible data breach, replacing … [...]

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading