Cyber criminals target SA’s CIPC business registry

cyber security data protection Mar 2024

The Companies and Intellectual Property Commission (CIPC) has officially reported an "attempted security breach" resulting in the unauthorized exposure of personal information belonging to both employees and clients.

In a statement released last week, the CIPC formally notified recipients, stating, "You are hereby informed that the CIPC has detected an attempted security breach leading to the compromise of personal information belonging to clients and CIPC employees, as stored in the CIPC records.

"Our Information and Communication Technology (ICT) technicians, prompted by the robust firewall and data protection systems in place at the CIPC, were alerted to a potential security compromise. Consequently, certain CIPC systems were promptly deactivated to minimize potential damage.

"Through the diligent efforts of our ICT and information security teams, the breach was successfully isolated and contained, allowing for the restoration of relevant systems, which are now operational for processing.

"Regrettably, unauthorized access to and exposure of specific personal information of both our clients and CIPC employees did occur."

The CIPC, an agency under the Department of Trade, Industry, and Competition in South Africa, oversees the registration of companies, co-operatives, and intellectual property rights (trademarks, patents, designs, and copyright), along with their maintenance.

"CIPC clients are strongly advised to exercise vigilance in monitoring credit card transactions and to approve only known and valid transaction requests," emphasizes the CIPC.

The investigation into the extent of the exposure is currently underway, and findings will be communicated promptly.

Acknowledging the critical importance of consistent system availability and the protection of non-public information, the CIPC is actively engaged in minimizing any potential impact on its clients and employees.

"We extend our sincere apologies for any inconvenience caused and assure you that every reasonable measure is being taken to ensure the safety and protection of all CIPC systems and platforms against unauthorized and/or unlawful access."

The incident at CIPC aligns with a broader trend of data breaches within South African organizations. Advocate Pansy Tlakula, chairperson of the Information Regulator, has stated that South Africa is currently experiencing an "open season for security compromises," with the regulator receiving over 150 data breach notifications monthly.

Nomzamo Zondi, spokesperson for the Information Regulator, confirms that as of January 2024, the regulator has received 224 security compromise notifications. The Information Regulator, mandated to enforce data privacy measures under the Protection of Personal Information Act (POPIA), requires organizations to inform them of any unauthorized exposure of personal information to third parties.

POPIA outlines stringent frameworks for companies to follow to avoid fines, criminal prosecution, and potential damage to their reputation. Perpetrators can face fines of up to R10 million or 10 years of imprisonment, depending on the severity of the breach.

The Information Regulator has been informed of the CIPC incident, ensuring alignment with regulatory requirements and procedures.

StormWarning! CyberSecurity Consultants

Is your organisation properly Cybersecurity Hardenned and also Privacy Legislation compliant?..

                           ...Best you contact StormWarning! today not only will we will do our very best to answer that question for you and your organisation, but we will diligently endeavor to assist your organisation become Privacy legislation compliant and offer reliable CyberSecurity solutions while adhering to the constraints of your budget.

CONTACT US NOW!

 SOME CYBER SECURITY STATISTICS TO CONSIDER

How many cyberattacks per day?
According to Security Magazine, there are over 2,200 attacks each day which breaks down to nearly 1 cyberattack every 39 seconds.

How many people get hacked each year?
With around 2,220 cyberattacks each day, that equates to over 800,000 attacks each year.

What percentage of cyberattacks include a social engineering aspect versus a technical problem?
According to Cybint, nearly 95% of all digital breaches come from human error.

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.