
The Companies and Intellectual Property Commission (CIPC) has officially reported an "attempted security breach" resulting in the unauthorized exposure of personal information belonging to both employees and clients.
In a statement released last week, the CIPC formally notified recipients, stating, "You are hereby informed that the CIPC has detected an attempted security breach leading to the compromise of personal information belonging to clients and CIPC employees, as stored in the CIPC records.
"Our Information and Communication Technology (ICT) technicians, prompted by the robust firewall and data protection systems in place at the CIPC, were alerted to a potential security compromise. Consequently, certain CIPC systems were promptly deactivated to minimize potential damage.
"Through the diligent efforts of our ICT and information security teams, the breach was successfully isolated and contained, allowing for the restoration of relevant systems, which are now operational for processing.
"Regrettably, unauthorized access to and exposure of specific personal information of both our clients and CIPC employees did occur."
The CIPC, an agency under the Department of Trade, Industry, and Competition in South Africa, oversees the registration of companies, co-operatives, and intellectual property rights (trademarks, patents, designs, and copyright), along with their maintenance.
"CIPC clients are strongly advised to exercise vigilance in monitoring credit card transactions and to approve only known and valid transaction requests," emphasizes the CIPC.
The investigation into the extent of the exposure is currently underway, and findings will be communicated promptly.
Acknowledging the critical importance of consistent system availability and the protection of non-public information, the CIPC is actively engaged in minimizing any potential impact on its clients and employees.
"We extend our sincere apologies for any inconvenience caused and assure you that every reasonable measure is being taken to ensure the safety and protection of all CIPC systems and platforms against unauthorized and/or unlawful access."
The incident at CIPC aligns with a broader trend of data breaches within South African organizations. Advocate Pansy Tlakula, chairperson of the Information Regulator, has stated that South Africa is currently experiencing an "open season for security compromises," with the regulator receiving over 150 data breach notifications monthly.
Nomzamo Zondi, spokesperson for the Information Regulator, confirms that as of January 2024, the regulator has received 224 security compromise notifications. The Information Regulator, mandated to enforce data privacy measures under the Protection of Personal Information Act (POPIA), requires organizations to inform them of any unauthorized exposure of personal information to third parties.
POPIA outlines stringent frameworks for companies to follow to avoid fines, criminal prosecution, and potential damage to their reputation. Perpetrators can face fines of up to R10 million or 10 years of imprisonment, depending on the severity of the breach.
The Information Regulator has been informed of the CIPC incident, ensuring alignment with regulatory requirements and procedures.
Is your organisation properly Cybersecurity Hardenned and also Privacy Legislation compliant?..
...Best you contact StormWarning! today not only will we will do our very best to answer that question for you and your organisation, but we will diligently endeavor to assist your organisation become Privacy legislation compliant and offer reliable CyberSecurity solutions while adhering to the constraints of your budget.
SOME CYBER SECURITY STATISTICS TO CONSIDER
How many cyberattacks per day?
According to Security Magazine, there are over 2,200 attacks each day which breaks down to nearly 1 cyberattack every 39 seconds.
How many people get hacked each year?
With around 2,220 cyberattacks each day, that equates to over 800,000 attacks each year.
What percentage of cyberattacks include a social engineering aspect versus a technical problem?
According to Cybint, nearly 95% of all digital breaches come from human error.