Just got the official mail.
Really poor show that they can do this with no repercussions.
Dear Michael,
We are contacting you following your recent cashback claim that you made through our SystemActive Reverb site. We wanted to make you aware that, owing to a misconfiguration of the cashback claim website, some personal information related to the claim was accessible online.
While this error was swiftly corrected, we wanted to make you aware of the incident.
What happened?
We were recently made aware that some customer information on our SystemActive Reverb cashback site was accessible online. We immediately launched an urgent investigation. Our current understanding is that this information could, in theory, have been accessed. However, this was only via customer-specific URLs and then manually drawing out the data from the site source code. There is no indication at the moment that anyone malicious or anyone other than the individual who flagged this issue has accessed the data in this way or was aware that the data could be accessed in this way.
Following our investigation, we have informed the Information Commissioner's Office (ICO - the UK's data protection authority).
What information was involved?
As a precautionary measure, we’re contacting SystemActive customers who accessed the cashback offer before 6th January
2021. The data that was temporarily and theoretically available via the back end of the site includes your name, address, telephone number, bank account details, PDF invoice of purchase and claim number.
It is important to note that your bank account number was heavily encrypted using 256bit key and therefore was not accessible at any point
Our response and next steps
I can confirm that the issue has been resolved and the data was secured within 30 minutes of the issue having been brought to our attention. The matter is being investigated as a top priority and we will keep you informed of any relevant updates.
I hope that you can see that we have taken this incident extremely seriously. I’d like to stress that this is an isolated incident and not indicative of our approach to IT security. We have never experienced an incident like this in our history, but this is a timely reminder of the importance of data security.
If you have any concerns or questions on the above, please do get in contact with our Customer Service Team on telephone
- 0333 880 5980 or email -
[email protected].
Best wishes,
Consenna.