Desjardins credit union announced a data breach that exposed personal banking information of 2.9 million customers.
The nation’s largest credit union, one of the largest in the world, confirmed it suffered a data leak that exposed personal banking information of 2.9 Million customers. The security breach occurred in December, but law enforcement only revealed it last Friday. Data was leaked after an ill-intentioned employee disclosed it to people outside the organization without any authorization.
Compromised data, including 2.7 million individual members and 173,000 business members, were shared by intruders outside the organization.
“A Laval police investigation, which Desjardins has been closely involved with, has revealed that the personal information of 2.9 million members (2.7 million personal members and 173,000 business members) was disclosed to individuals outside Desjardins without authorization.” reads a statement published by the company.
“The investigation quickly traced the leak to a single source: an ill-intentioned employee who acted illegally and betrayed the trust of their employer. That person was fired.
In light of these events, additional security measures have been put in place to ensure all our members’ personal and financial data remains protected.”
Exposed data include names, date of birth, contact information and banking habits, fortunately, passwords and other security information were not exposed.
The employee responsible for the data leak has since been fired, and the Police initially arrested him and after then released him while its investigation continues.
The company announced additional security measures to avoid such kind of incident in the future.
Desjardins Credit union will refund eventually frauded members and would offer free credit monitoring to impacted ones.
“This major incident affecting Desjardins Group today puts into perspective the omnipresent risk that now weighs on all organizations in terms of information security risks,” Quebec’s financial sector regulator said in a statement.
Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer.
Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US.
Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines.
Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.