PAMGOLDING DATA BREACH @KASIBCNEWS
PAMGOLDING DATA BREACH @KASIBCNEWS
RE: NOTIFICATION OF SECURITY COMPROMISE IN TERMS OF SECTION 22(1)(b) OF THE PROTECTION OF PERSONAL INFORMATION ACT 4 OF 2013 ("POPIA")
- We are writing to inform you of an incident involving your personal information. In line with our commitment to data protection and our obligations under POPIA, we wish to promptly bring this matter to your attention.
- On 7 March 2025, we discovered a security compromise on our Alchemy system, a customer relationship management system hosted on servers in South Africa, which may have resulted in unauthorised access to some of your personal information which is stored on our system.
- A third party outside of South Africa (unknown to us at this stage) gained unauthorised access to our system using an email account and queried our database. As soon as we became aware of the incident, we took immediate action to secure our systems by removing all unauthorised access and investigated the impact of this incident.
- It is important to note that no banking details, financial information, commercial information and/or other documents were compromised.
- We take this incident seriously and will be taking the following steps (immediately and in the short term) to contain the incident and prevent any further recurrence:
- 5.1 the affected user account password was changed and secured, and all active sessions have been terminated;
- 5.2 we have reset passwords for all our user accounts system-wide;
- 5.3 our team has reviewed all system access logs to determine the extent of the breach and identify any affected data;
- 5.4 we will patch any potential vulnerabilities and reinforce our security protocols;
- 5.5 we will implement any additional monitoring tools to detect and respond to any future suspicious activity;
- 5.6 we are in the process of appointing independent cybersecurity specialists to investigate the incident and provide recommendations for enhanced security; and
- 5.7 over and above our existing access control measures, we will enhance these further and adopt the appropriate recommendations of cybersecurity specialists.
- While we are still investigating the full scope of the incident, we want to make you aware of potential risks:
- 6.1 a third party accessed our system using an active user account. If your information was involved, it may have been viewed or queried;
- 6.2 cybercriminals sometimes use stolen information to send fraudulent emails or messages pretending to be from trusted sources; and
- 6.3 if personal details were accessed, there is a small risk of identity fraud, though we have no evidence of misuse at this time.
- Please be assured that we are still in the process of investigating this incident and will be implementing additional security measures to minimise the effect of this security compromise.
- In the interim, we advise you to be cautious about clicking on links and providing sensitive information, including bank pins and user login passwords. If you are suspicious that a person other than one of our authorised agents is attempting to contact you or obtain your personal information, please contact our Information Officer or the agent who you usually deal with.
- We take your privacy commitments under POPIA seriously. We regret any inconvenience this may cause and are committed to strengthening our security measures to protect your information.
- If you have any questions or require further assistance, please do not hesitate to contact our Information Officer, at informationofficer@pamgolding.
co.za
Comments
Post a Comment
KASIPEOPLE