OFX Faces Unresolved Privacy Risk After Unauthorised Data Access

OFX Group is investigating unauthorised access to data involving some clients and people who have interacted with the company. The fintech says there is currently no evidence that client accounts, funds or services were affected, but the scope of the incident remains unclear.

  • Unauthorised access to client-related and applicant data under investigation
  • No unauthorised access to client accounts or funds identified so far
  • No client financial loss reported based on information currently available
  • Identity documents do not appear to have been accessed
  • Australian and overseas regulators have been notified
An image related to Ofx Group Limited Add us as a preferred source on Google
Image © middle. Logo © respective owner.

OFX Contains Data Access Incident

OFX Group Limited (ASX:OFX) is investigating a cybersecurity incident involving unauthorised access to data linked to some clients. The company said its IT and security teams responded immediately after discovering the incident and have implemented containment measures.

The immediate financial picture is, for now, less severe than the data breach itself might suggest. OFX has not identified unauthorised access to client accounts or funds and said that, based on information available to date, there has been no financial loss to clients. Its services and systems remain operational and fully available.

Affected Individuals and Data Remain Unconfirmed

OFX has not yet established the identity or number of clients whose data may have been accessed. The company said it does not currently appear that copies of identity documents were involved, while the data accessed also appears unable to be used to make a payment through the OFX platform.

The potential exposure may extend beyond customers. OFX said data relating to people who interacted with the company in non-client capacities, including job applicants, may also have been accessed. That leaves the company still determining not only who was affected, but precisely what information was involved.

Regulatory Notifications Add Pressure

OFX has notified the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and other global regulatory authorities. The investigation is continuing as a matter of urgency, with the company saying it will contact affected clients and individuals once it can confirm their data was accessed.

For shareholders, the central uncertainty is not an identified loss of funds but the unfinished forensic work. The eventual number of affected people, the categories of data involved, any required remediation and the response from regulators will determine whether the incident remains a contained privacy event or develops into a more material operational and reputational problem.

Bottom Line?

OFX has reported no affected funds or service interruption so far, but the investment risk will turn on the still-unknown scope of the data access and any remediation or regulatory consequences.

Questions in the middle?

  • How many clients, applicants and other individuals were affected?
  • What categories of personal data were accessed, and was any information copied or removed?
  • Will the investigation lead to remediation costs, regulatory action or changes to OFX’s security controls?

Sources

1