iTnews
  • Home
  • News
  • Technology
  • Security

First State Super breached privacy law

By John Hilvert
Jun 7 2012 11:07PM
Follow google news

Security researcher cleared.

Superannuation firm First State Super has been found in breach of the Privacy Act after exposing sensitive data to existing customers on its website.

First State Super breached privacy law

In a final report [pdf] released yesterday, Privacy Commissioner Timothy Pilgram found the company in breach of the National Privacy Principles (NPPs) in the Privacy Act because it did not have adequate security measures in place to protect customer information from unauthorised access and disclosure.

Though First State Super did not disclose information to a third party, the commissioner found the firm had not taken reasonable steps to protect the personal information held in the members section of its website.

An investigation by the commissioner after the breach in October 2011 found the company had "conducted a number of tests of sample web pages prior to the incident", including 200 internal examinations, but failed to properly test the area found to be vulnerable to attack by existing customers.

Specifically, Pilgrim found internal audits by parent company Pillar should have detected the flaw. This resulted in a breach of NPP 4.1 of the Privacy Act.

"In my view, FSS would have had the capacity to remedy this flaw in its system. For this reason I found that FSS had failed to take reasonable steps to protect the personal information it held, and had breached the Privacy Act,” Pilgrim said.

The commissioner did not impose penalties against the company, however, because it moved to patch the security holes and immediately informed customers.

“Incidents such as this are very concerning particularly when sensitive personal details, such as financial information are accessed by an unauthorised person,” Pilgrim said.

“I acknowledge the speed with which FSS acted when they became aware of the incident, immediately containing the incident, notifying affected members and commencing an internal investigation.”

The company hit headlines last year after issuing legal threats against OSI Security consultant and penetration tester, Patrick Webster, for finding and reporting the security holes to the company.

An existing customer with the fund, Webster had informed IT staff at First State Super about the hole and provided them with a proof of concept which accessed 578 customer accounts, including members' names, addresses, superannuation account details and balances.

First State Super served Webster with legal proceedings [pdf], demanding he hand his computer to the company’s IT staff to ensure data was removed.

Charges and an investigation by NSW Police have since been dropped. The commissioner also cleared Webster of wrongdoing in his report.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
breachpilgrimpressgalleryprivacyprivacy actsecurity

Related Articles

  • Anthropic releases Mythos-class model for public use Anthropic releases Mythos-class model for public use
  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
Join our WhatsApp Channel

Partner Content

You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
AI is delivering business value today
Partner Content AI is delivering business value today

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.