"This was an error on the bureau’s part in the execution of that distribution. The affected file contained a list of customer email addresses only. It did not contain separate fields with customer names, loan account numbers, loan balances, Taxpayer Registration Numbers (TRNs), dates of birth, residential addresses, telephone numbers, banking information, passwords or other account credentials," said the SLB.
SLB said the error affected only one batch of the distribution. "The file was not published on SLB’s website, social media channels or other public platforms. The bureau is continuing to verify the final scope of the affected distribution and whether there is any evidence of further dissemination.
The incident did not alter any customer’s loan account, balance, repayment obligation or account status. There is currently no indication that the incident resulted from unauthorised access to SLB’s systems or from malicious activity. The matter was identified and escalated for investigation on the same day it occurred," the bureau added.
The bureau said it has initiated a review of the incident and of the controls governing bulk customer communications, including confirmation of the scope of the affected distribution and the implementation of additional safeguards to reduce the possibility of a recurrence. "Bulk email distributions using the affected process have been suspended while additional safeguards are implemented. The matter has been reported to the Office of the Information Commissioner in accordance with applicable requirements.
Customers identified as affected are being contacted directly by the bureau," the SLB said. It noted that as a precaution, customers should remain vigilant for suspicious or unsolicited communications that may appear to originate from the bureau.
Summary from source