By Lehlohonolo Lehana.
Credit reporting agency TransUnion South Africa says that at least three million South Africans have been impacted by a data hack earlier this month.
TransUnion was compromised by the hacker group ‘N4aughtysecTU’ which demanded a $15 million (R225 million) ransom over four terabytes of compromised data. The hacker group claims the information in its possession contains everything from credit scores to banking details and ID numbers.
TransUnion South Africa initially issued a statement confirming that a criminal third-party obtained access to an isolated South African server, through misuse of an authorised client’s credentials – however, this was deemed an ‘inadequate response’ by the country’s information regulator.
In a follow-up statement published on Saturday (26 March) TransUnion went into more detail about the attack.
The group confirmed that its systems were breached, but stressed that the hackers targeted an “isolated server”, holding limited data on South African clients. It said that hackers have aggregated data, including the details of 54 million South Africans from a previous leak in 2017, unrelated to the latest incident.
“We are aware that a criminal third party has aggregated and is releasing data allegedly obtained from TransUnion South Africa and other sources, including at least 54 million records unrelated to TransUnion from prior data breaches dating back to 2017,” it said.
“With the help of outside experts, we are screening and reviewing this data as quickly as we are able to safely access it.”
The group said it will not pay the ransom demand.
Who was affected?
TransUnion said that its latest investigations showed that detailed information from three million South Africans was captured in the hack.
Six million more ID numbers were also identified where there is no personal information linked to the ID numbers that would enable the group to identify the impacted consumers or to communicate with them directly at this stage.
“At this time TransUnion South Africa can confirm at least three million impacted consumers. We continue to work diligently to determine whether (the six million additional) ID numbers can be linked to other personal information to identify any additional impacted consumers,” it said.
What was stolen?
The stolen data includes:
- Name;
- ID number;
- Date of birth;
- Gender;
- Contact details;
- Marital status and information;
- Identity of employer and duration of employment;
- Vehicle finance contract number;
- VIN numbers.
In isolated circumstances, spouse information, passport numbers, credit or insurance scores may be impacted, TransUnion said.
“Each data subject may have a combination of different fields impacted, depending on what data was available.”
What to do next
TransUnion said that while it is conducting its investigations with authorities and external experts, South Africans should remain vigilant and be on alert for any fraudulent activity.
It said it would be getting into contact with consumers and business customers it believes have been affected.
As this is happening, the group said it will be providing information on how affected individuals can protect themselves, including a free annual subscription to TransUnion’s tools to detect identity-related threats, as well as free access to their credit report and alerts up to 31 December 2023.
“If anyone is uncertain of communication that appears to come from TransUnion, we recommend visiting our website instead. Please be vigilant of phishing attacks and remember that a TransUnion representative will never ask for your banking details, bank PIN or user login password,” it said.
Additional information can be found on the group’s FAQ page.
