The NCR Website is displaying a banner saying that they have been the victims of a cyber attack.
Data Breach
The NCR have an extensive database of all registered Debt Counsellors, Credit Providers, Credit Bureaus and Payment Distribution Agents.
This public database is easily found on the website and is designed to provide visibility and clarity for any consumers wanting to check that someone they are dealing with (for a loan or debt counselling) is really registered with the NCR.
The NCR also has another, more extensive database of all consumers who have ever asked a Debt Counsellor for assistance or professional advice. Debt Counsellors regularly update this database (Called NCR Debt Help).
The NCR also collect and compile information from credit bureaus and credit providers.
There have recently been several concerned parties within the industry who were worried that the NCR site may be vulnerable and that it may be possible to find information that could be considered private and confidential. In light of PoPI requirements, everyone these days worries about data security and what bad people may do if they find sensitive data.
In September this year, the NCR was a victim of a website hack.
This caused the website to redirect, and Google search results to come back with weird results pointing to the Ministry of Islamic Affairs:
When you went to their site (www.ncr.org.za) you got this stripped down version of the website:
The NCR site also looked like this for a while when you searched for a registrant:
The website attack happened days after the NCR conducted a series of raids on churn mill operations in the Western Cape (A scam where people are signed up for debt review and then have to pay to leave debt review without any work actually having happened). This led to a lot of speculation about whether it was perhaps retaliatory.
Once aware, the NCR took steps to get the site back up and running.
Official Notice Issued
The NCR have issued an official notice that they have had a data breach and have been a victim of a cyber attack.
They have made a few cautionary suggestions and say they have reported the matter to all relevant parties.
The notice was issued 12th December but it does not state when the cyber attack occurred. So, it may relate to the September breach or one more recently.
We use cookies (the computer type not the tasty ones) to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.Yummy, Cookies... OKNo