Payday lender Wonga admits to data breach
270,000 customers advised not to worry but also to watch out for odd transactions and ponder password refresh
Payday lender Wonga has advised 270,000 customers of a data breach and offered inconsistent advice about the severity of the incident and how to respond.
An “incident FAQ” on the company's site says “We believe there may have been illegal and unauthorised access to the personal data of some of our customers.” The Reg understands 270,000 customers are potentially at risk, 245,000 of them in the UK.
Wonga says the data that parties unknown have accessed “may have included one or more of the following: name, e-mail address, home address, phone number, the last four digits of your card number (but not the whole number) and/or your bank account number and sort code.”
The FAQ offers contradictory advice on the incident, offering assurances that “We believe that your account is secure and you do not need to take any action" but also says “if you are concerned you should change your account password. We also recommend that you look out for any unusual activity across any bank accounts and online portals.”
The FAQ, and a letter sent to affected customers, also offers the following advice:
Exercise vigilance: Beware of scammers or unusual online activity. Be cautious of anyone who calls you and asks you to disclose any personal information regardless of where they say they are from. If this happens, we recommend that you hang up.
The Register has asked Wonga to clarify why customers need to keep an eye on “unusual activity” if their accounts remain secure and why they might experience inbound scam calls at this time.
Wonga says it is informing customers' banks of the situation, to help them detect any fraud.
The FAQ also asks the question “How did this happen in the first place and what measures are you taking to ensure that this does not re-occur?” and offers the following as a response:
- We take issues of customer data and security extremely seriously.
- Cyber attacks are, unfortunately, on the rise. While Wonga operates to the highest security standards, these illegal attacks are unfortunately increasingly sophisticated.
- We sincerely apologise for the inconvenience and concern this has caused.
Which The Register rates a masterpiece of evasion and obfuscation, even among the deluges of press releases and non-answers we receive each day.
Wonga charges annual interest rates of 1,509 per cent (yes, one thousand five hundred and nine per cent) for short-term loans designed to tide people over until payday. The company justifies its interest rates on grounds of convenience and value.
The PR people have made contact again hours after this article was published:
"Wonga is urgently investigating illegal and unauthorised access to the personal data of some of its customers in the UK and Poland. We are working closely with authorities and we are in the process of informing affected customers. We sincerely apologise for the inconvenience caused." ®
Sponsored: Becoming a Pragmatic Security Leader