Image created by AI

TransUnion Faces Enforcement Action by Information Regulator for Data Breach in South Africa

Published March 28, 2024
2 years ago


TransUnion, a leading credit bureau in South Africa, has come under the scanner of the country's Information Regulator due to a significant data breach that took place on March 18, 2022. Subsequent to the incident, the Information Regulator has issued an enforcement notice to the credit bureau, a move indicating the gravity of the data privacy violation and the regulatory body's commitment to protecting consumer data.


The breach, claimed by the hacker group N4ugthySecTU, reportedly resulted in the exfiltration of approximately 4TB of data from TransUnion, affecting records of millions of South Africans. Initial statements by TransUnion acknowledged that at least 3 million customers had been affected, with a subsequent exposure of 6 million ID numbers that were not paired with additional personal information. These figures were later revised to 5 million consumers potentially affected, with an additional 5.2 million consumers having their ID numbers exposed.


In a bold stance against cyber extortion, TransUnion refused to comply with the hacker group's demand for a $15 million (R224 million at the time) ransom to prevent the leaked data from being circulated online.


The response from the Information Regulator arrived swiftly, criticising TransUnion for notification processes that failed to meet the requirements of the Protection of Personal Information Act (POPIA). The assessment conducted by the Regulator led to a stark conclusion: TransUnion had breached the conditions for lawful processing of personal information.


In light of this breach, the enforcement notice detailed three compulsory remedial measures for TransUnion. First, the company must implement robust security measures to protect the integrity and confidentiality of the personal information it manages. Second, the services of a qualified auditor must be engaged to audit user accounts, ensuring they are in line with TransUnion's Secure File Transfer Protocol (SFTP) user creation policy. Lastly, TransUnion is required to conduct a thorough personal information impact assessment to affirm compliance with POPIA.


TransUnion faces a deadline of May 26, 2024, to provide evidence confirming that these remedial steps have been effectively put into action as per the requirements of the Information Regulator.


The enforcement notice sent to TransUnion serves as a firm reminder to all companies that the handling of personal data requires the utmost security and care. It also underscores the proactive role that regulatory bodies must take in the wake of data breaches, ensuring organizations are held accountable for protecting consumer information.



Leave a Comment

Rate this article:

Please enter email address.
Looks good!
Please enter your name.
Looks good!
Please enter a message.
Looks good!
Please check re-captcha.
Looks good!
Leave the first review