Share

Ashley Madison hack 'a lesson' for SA firms

Cape Town - The data dump by the AshleyMadison.com hackers is a warning to South African firms on the importance of securing client information, says a local expert.

Hacker group The Impact Team stole over 30 million users' personal and financial information from the cheating website.

"In the case of the Ashley Madison website, it is interesting to note that the apparent driving factors for The Impact Team's hack is related to moral reasoning, where they are attempting to stand up against the use of the website which enables people in relationships to cheat on their partners," said Candice Sutherland, business development consultant at Stalker Hutchison Admiral Specialist Underwriters.

"The nightmare may not be over for the victims as the hackers still have over 290GB of photos and emails which are yet to be released," said Sutherland.

In Canada, Ashley Madison is already facing a $578m class action lawsuit over the breach.

If this breach had to happen to a South African company, Sutherland indicated that heavy fines could be imposed.

This is because local companies that fail to take adequate measures to protect client information on the internet could find themselves in breach of the Protection of Personal Information (Popi) Act.

"Popi aims to give effect to the constitutional right to privacy and therefore restricts the unauthorised access to information regarding the educational, medical, financial, criminal or employment history of an individual as well as their personal details such as ID numbers, contact details and physical addresses," Sutherland said.

"In addition, all personal details that are shared with an organisation in confidence, be it race, gender, marital status, religion, culture, sexual orientation and even language, are protected under Popi legislation and a breach of the act can result in a fine of up to R10m or 10 years in prison."

A regulator for Popi has yet to be appointed, but South African companies are still expected to toe the line.

Data loss protection

South African companies could also be particularly exposed if an Ashley Madison style breach had to happen locally.

According to a report from security specialist firm Trustwave, only 38% of local companies said that they had organisational measures in place to prevent the loss of unauthorised data.

And in the event of a data breach, the risk is that few local organisations would even divulge data loss.

"In South Africa, no. Nobody's going out there to publically announce that they had a data breach. That would be quite catastrophic for them. However, I do agree that there is a responsibility with that company to go through that process to notify you - not 32 days later," Andrew Kirkland, Trustwave regional director for Africa told Fin24 recently in reference to a high profile Sony attack.

Do you think local companies are doing enough when it comes safeguarding your information online? Tell us by clicking here.

- Follow Duncan on Twitter

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.19
+0.1%
Rand - Pound
23.97
-0.1%
Rand - Euro
20.57
-0.1%
Rand - Aus dollar
12.50
-0.1%
Rand - Yen
0.12
+0.3%
Platinum
912.90
+0.1%
Palladium
1,004.00
-0.1%
Gold
2,318.11
+0.1%
Silver
27.17
+0.0%
Brent Crude
88.02
-0.5%
Top 40
68,574
0.0%
All Share
74,514
0.0%
Resource 10
60,444
0.0%
Industrial 25
104,013
0.0%
Financial 15
15,837
0.0%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders