We'd like to remind Forumites to please avoid political debate on the Forum. This is to keep it a safe and useful space for MoneySaving discussions. Threads that are - or become - political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

Possible breach of data?

craggs
craggs Posts: 256 Forumite
Part of the Furniture 100 Posts Name Dropper Combo Breaker
Hi

I am wondering if anyone could advise.

I logged into my energy account 2 nights ago and noticed my direct debit changed and the credit on my account everytime I refreshed my page.

Then my account number change and another name came up.I was able to access another account,infact 2 names came up,but with one my account number stayed the same.

I did screen shots and contacted my energy company,who asked for them.

They have gotten back to me and admitted an updated caused a small number of accounts to cross access and they are looking into it how much data could of been accessed,if any,although I was able to access another persons account.I provided them with there name and account number.

They want me to delete the screenshots,and they have apologised.

Im not sure what if anything I can do,I have for now not deleted the evidence.I don't know what steps to take,if this is serious or not so bad.

I don't want to name the company ,certainly not for now.

Thank you
Dony worry,be happy...

Comments

  • wavelets
    wavelets Posts: 1,164 Forumite
    1,000 Posts Combo Breaker
    edited 8 December 2018 at 9:14AM
    craggs wrote: »
    Hi

    I am wondering if anyone could advise.

    I logged into my energy account 2 nights ago and noticed my direct debit changed and the credit on my account everytime I refreshed my page.

    Then my account number change and another name came up.I was able to access another account,infact 2 names came up,but with one my account number stayed the same.

    I did screen shots and contacted my energy company,who asked for them.

    They have gotten back to me and admitted an updated caused a small number of accounts to cross access and they are looking into it how much data could of been accessed,if any,although I was able to access another persons account.I provided them with there name and account number.

    They want me to delete the screenshots,and they have apologised.

    Im not sure what if anything I can do,I have for now not deleted the evidence.I don't know what steps to take,if this is serious or not so bad.

    I don't want to name the company ,certainly not for now.

    Thank you

    You've done part of what you need to do - and the supplier is now doing what they need to do ... according to the information you have provided here, ... at least for now :)

    All that is left for you to do at this time is follow the intructions provided to you by the supplier.

    Edit: On a more positive note, may I be the first to provide you with a warm welcome back to MSE following a 4 year posting hiatus.
    https://forums.moneysavingexpert.com/showpost.php?p=74780609&postcount=279
  • If you wish, you could inform the Information Commissioner's Office
    https://ico.org.uk/make-a-complaint/
  • t0rt0ise
    t0rt0ise Posts: 4,350 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    It was a mistake. They've corrected it. No need to take it further.
  • kim81
    kim81 Posts: 15 Forumite
    Sounds like they are on top of things. You could change your password just to be on the safe side.
  • Im not sure what if anything I can do,I have for now not deleted the evidence.I don't know what steps to take . . .
    How much do you want?
  • badmemory
    badmemory Posts: 8,711 Forumite
    Eighth Anniversary 1,000 Posts Name Dropper
    but it should be necessary to ask that whilst they have corrected this specific "mistake" have they corrected the other similar ones caused by the same problem!
  • Grey_Critic
    Grey_Critic Posts: 1,347 Forumite
    Eighth Anniversary 1,000 Posts Name Dropper Combo Breaker
    Of course you should report it. Why have a Data Protection Act if nobody does anything when it gets broken.
  • craggs
    craggs Posts: 256 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker
    How much do you want?

    How much??
    Dony worry,be happy...
  • craggs
    craggs Posts: 256 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker
    badmemory wrote: »
    but it should be necessary to ask that whilst they have corrected this specific "mistake" have they corrected the other similar ones caused by the same problem!


    Unsure,I have been back InTouch and they don't actually know how much data has been leaked.If I was able to access another person's acount,name,address,bills ,then I guess it works both ways,they also don't know how many,I have asked that.

    I'm unsure if they have contacted other either.
    Dony worry,be happy...
This discussion has been closed.
Meet your Ambassadors

Categories

  • All Categories
  • 347.2K Banking & Borrowing
  • 251.6K Reduce Debt & Boost Income
  • 451.8K Spending & Discounts
  • 239.5K Work, Benefits & Business
  • 615.3K Mortgages, Homes & Bills
  • 175.1K Life & Family
  • 252.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 15.1K Coronavirus Support Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.