AB
Andries B

1 reviews | Active since Mar 2019

18 Mar 2019, 16:10

Edgars Account Method Cyber Risk

I received an e-mail, possibly from Edgars, but no guarantee. The e-mail asks me to click on a link, then enter my ID number as password. When I confonted Edgars with this cyber security risk, they indicated that this was the only way to access your account. When I tried to escalate the matter, the call center told me to call head office. Head office routed the call to the call center. The final response I got was a copy of my account mailed to me.

Here lies the risk. Nothing prevents me to send you a mail from a dummy Edcon account, ask you to verify your 19 digit Edgars account number, use your ID to log in and then ask you to update your address details. Final step is to route you to a dummy error 404 page. With this information I can borrow R 150 000-00 through Direct Axis, part of the Edcon stable.

Edcon does not see this action of theirs as terrible decision making regarding cyber security, basically putting all their clients at risk for phishing as well as distribution of personal information.

0
Replies (2)
Edgars
Edgars's reply19 Mar 2019, 12:16
Official
Dear Andries, 

Kindly note our format to view monthly statement has changed to E-statement format.  
The method is implemented so that the main account holder can only be the one that  has visibility of his/her own statement.
 The link to access the statement is on the body of the email, and not on the attachment. 

The link opens up to a summary of your transactions. 

To view your full statement: 

  • Scroll to the view of the full statement option at the bottom of the page
  • Click on the full statement view Option.
  • Insert your 13 digit South African ID number or account/card number if you do not hold a South African ID in order to open your statement.

Rest assured by using the above instructions your details will not be at risk.

Your reference number is:
***/GO
 NB: Please be advised that we have requested a copy of your latest statement to be sent to you via email and you will receive your statement within 48 hours. 

We apologise for the inconvenience caused. 
Should you require any further assistance, please do not hesitate to contact us on the number provided. 

Kind Regards
The Edgars Team 
*** 



Best regards,

AB
Andries B's update20 Mar 2019, 20:33
Reviewer Update
Dear Edgars Team This response is exactly why I listed the complaint on hellopeter.com. I have no interest in getting a mail from Edgars as long as the mails have embedded links to websites. This is a cyber-security risk. Please refer this issue to your auditors who may have a cyber-security expert to explain to you why an embedded link in an e-mail is the easiest way to ***** personal information. Maybe your lawyers can also explain why giving cyber ******* this opportunity transgresses the POPI Act. Even better, the fact that I warned you, basically gives every client de*****ed by people using this approach the right to sue you with ease. To compound matters and prove that your protection of personal information via this method is inadequate, the first response I got from you shared another client’s information with me. I would also assume that the promised response may end in someone else’s inbox, *******ly sharing my personal information. Please take this issue serious. Edgars is opening all its client accounts to potential phishing attacks due to a terrible security decision blunder. I would love a shareholder activist to ask the directors of Edgars why they allowed this to proceed. I will confirm the steps for laying a complaint with the information security regulator as defined in the POPI Act. Regards Andries Botha