Attacks/Breaches

4/11/2017
09:45 AM
50%
50%

UK Loan Firm Wonga Suffers Financial Data Breach

Customers in the UK and Poland may have had their bank account details compromised.

British payday loan company Wonga has admitted to suffering a data breach affecting 245,000 customers in the UK and probably 25,000 in Poland, BBC News reports. The company is investigating what is "looking like one of the biggest" data breaches in the country involving financial data.

What could be a serious issue in the Wonga breach is the likely theft of customer bank account details including sort codes and the last four digits of bank cards. Earlier major hacking incidents in the country, like those linked to Talk Talk and Yahoo, did not involve financial data.

Information Commissioner's Office has said "All organizations have a responsibility to keep customers' personal information secure. Where we find this has not happened, we can investigate and may take enforcement action."

The company does not think its loan account database has been compromised, but nevertheless asked customers to be alert. It has set up a helpline and help page for those affected.

Read more on BBC News.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/11/2017 | 3:21:10 PM
help page for those affected
In situations such as these the company should be liable for provided anti-fraud services. Potentially baked into cyber insurance, the peace of mind and brand reputation that the company would lose would be reduced based off the previous event of a breach.
Microsoft President: Governments Must Cooperate on Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/8/2018
The Morris Worm Turns 30
Kelly Jackson Higgins, Executive Editor at Dark Reading,  11/9/2018
Veterans Find New Roles in Enterprise Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12174
PUBLISHED: 2018-11-14
Heap overflow in Intel Trace Analyzer 2018 in Intel Parallel Studio XE 2018 Update 3 may allow an authenticated user to potentially escalate privileges via local access.
CVE-2018-3621
PUBLISHED: 2018-11-14
Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
CVE-2018-3635
PUBLISHED: 2018-11-14
Insufficient input validation in installer in Intel Rapid Store Technology (RST) before version 16.7 may allow an unprivileged user to potentially elevate privileges or cause an installer denial of service via local access.
CVE-2018-3696
PUBLISHED: 2018-11-14
Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivileged user to potentially gain administrative privileges via local access.
CVE-2018-3697
PUBLISHED: 2018-11-14
Improper directory permissions in the installer for the Intel Media Server Studio may allow unprivileged users to potentially enable an escalation of privilege via local access.