How to deal with a service provider breach

A man in a suit and tie is talking on his phone outdoors.

Navigation

Your generosity can provide a lifeline to victims of cybercrime

A service provider data breach occurs when a company, organisation, website or application you use experiences a cyber incident that exposes customer information.

Depending on the nature of the breach, criminals may gain access to information such as your:

  • Email address.

  • Username.

  • Password.

  • Phone number.

  • Identity information.

  • Payment details.

  • Personal communications.

Even if your financial information was not exposed, criminals may use your personal information to launch phishing attacks, commit identity fraud or attempt to access your other online accounts.

Use this guide if you have been informed that a service, application, company or website you use has experienced a data breach.

We want to better understand the impact of you experiencing this issue, can you share your experience by filling in this online form? This will help us better protect future victims.


What should I do first?

Every data breach is different. The impact may range from minimal inconvenience to significant financial or identity-related harm.

The following steps will help reduce your risk.

  1. Confirm that the notification is genuine - Cybercriminals sometimes exploit news of genuine breaches by sending fake emails or SMS messages pretending to come from the affected organisation.

    Before taking any action:

    • Visit the provider's official website directly.

    • Look for announcements about the breach.

    • Contact the organisation using the contact details published on its official website or mobile application.

    Do not click links or call telephone numbers contained in unexpected emails, SMS messages or instant messages.

  2. Find the providers official guidance - Most organisations publish detailed advice following a data breach.

    Read their official guidance carefully to understand:

    • What happened.

    • What information was affected.

    • What actions you should take.

    • What assistance the organisation is providing.

  3. Change your password immediately - If your account credentials may have been exposed:

    • Change your password immediately.

    • Use a strong, unique password that has never been used before.

    • Enable Multi-Factor Authentication (MFA) if it is available.

    If you used the same password on any other websites or applications, change those passwords immediately as well.

  4. Understand what information has been exposed - Find out exactly what information was compromised.

    For example:

    • Email address.

    • Password.

    • Mobile number.

    • South African identity number.

    • Banking or payment information.

    • Home address.

    • Personal messages.

    • Other sensitive information.

    The type of information exposed determines what additional steps you should take.

    If identity information has been compromised, monitor for signs of identity fraud.

    If banking information has been exposed, contact your bank immediately.

  5. Contact the service provider - If you require more information about your specific account, contact the provider directly.

    They may be able to tell you:

    • Whether your account was affected.

    • What information was exposed.

    • Whether there is evidence of unauthorised access.

    • What additional protective measures they recommend.

    Be aware that customer support services may experience delays following a major breach.

  6. Monitor updates - Investigations into data breaches often continue for days or weeks.

    Monitor official announcements from the affected organisation as new information may become available regarding:

    • The cause of the breach.

    • The information affected.

    • Additional protective actions.

    • Available customer support.

  7. Monitor your accounts - Remain alert for signs of misuse, including:

    • Unexpected password reset emails.

    • Login notifications.

    • Phishing emails or SMS messages.

    • Unauthorised transactions.

    • New accounts opened in your name.

    • Unexpected verification requests.

    Review the security settings on your important online accounts regularly.

  8. Use any support offered - Some organisations provide affected customers with free support, such as:

    • Credit monitoring.

    • Identity protection services.

    • Security software.

    • Dedicated customer support.

    Review the provider's official website to see what assistance is available.

  9. If your banking information has been exposed - If you believe your banking details or payment information may have been compromised:

    Contact your bank immediately using the official contact details available:

    • In your banking app.

    • On the back of your bank card.

    • On your bank's official website.

    Ask your bank to:

    • Monitor your accounts for fraudulent activity.

    • Block or replace affected cards if necessary.

    • Secure your online banking profile.

    • Investigate suspicious transactions.

    • Provide a reference number.

  10. If your identity information has been exposed - If information such as your South African identity number has been compromised, monitor carefully for signs of identity fraud.

    Where appropriate, you may also wish to contact the Southern African Fraud Prevention Service (SAFPS) for guidance regarding identity fraud prevention and Protective Registration.

    SAFPS states that Protective Registration is a free service intended to help protect consumers against identity fraud and impersonation. It is available where an identity has been compromised and in circumstances such as identity fraud, or lost or stolen identity documents.

    Follow SAFPS's current application process rather than assuming that Protective Registration is automatically required. SAFPS currently provides online application and email/application routes and may require supporting documentation, including identification and proof of address.

  11. If you are concerned about how the organisation handled your personal information - If you believe a company or organisation has improperly handled your personal information, or that your rights relating to the protection of your personal information have been violated, you may consider lodging a complaint with the Information Regulator of South Africa under POPIA.

    The Information Regulator provides a POPIA complaints process and allows complaints to be submitted using its prescribed process. Its current published guidance also provides a POPIA complaints email address and online services.

    The Information Regulator may be relevant where your concern relates to the handling or protection of your personal information. Follow the Information Regulator's current official complaint process.

    The Cyber Helpline does not determine whether an organisation has breached POPIA or provide legal advice. A complaint does not guarantee a particular outcome.

  12. Report crime - If the breach has resulted in:

    • Financial loss.

    • Identity theft.

    • Fraud.

    • Extortion.

    • Unauthorised access to your accounts.

    Report the matter to the South African Police Service (SAPS) by visiting your nearest police station.

    Ask for:

    • A case number.

    • A copy of your statement, if available.

    Keep copies of:

    • Breach notifications.

    • Emails.

    • Screenshots.

    • Correspondence with the provider.

    • Records of unauthorised transactions.

    Note: A data breach itself does not necessarily mean that a criminal offence has been committed against you. If you have experienced fraud, financial loss, identity theft or another criminal act, SAPS reporting may be appropriate.




How to minimise the damage of a service provider breach

  1. Have unique passwords for each account - Using unique passwords prevents criminals from accessing multiple accounts if one password is compromised.

    Prioritise unique passwords for:

    • Email.

    • Banking.

    • Government services.

    • Shopping accounts.

    Consider using a reputable password manager.

  2. Check if you have been pwned - the haveibeenpwned.com website, run by cyber security experts, is a great tool for understanding if your information has been hacked in known public breaches. If you are concerned that your email address has been exposed in previous public breaches, you can use a reputable breach notification service to determine whether your email address has appeared in known compromised datasets.

    If your email appears in a breach:

    • Change affected passwords immediately.

    • Ensure those passwords are not used anywhere else.

  3. Enable Multi-Factor Authentication( MFA) - Enable MFA wherever available, particularly for:

    • Email.

    • Banking.

    • Social media.

    • Cloud storage.

    • Online shopping.

    This provides significant additional protection if your password is compromised.

  4. Strengthen your overall cyber security- Reduce your exposure by:

    • Keeping devices updated.

    • Being cautious of phishing emails and SMS messages.

    • Reviewing account security settings regularly.

    • Using reputable antivirus software.

    • Monitoring your important online accounts for unusual activity.

  5. Review provider security settings - Many online services include additional security features that are not enabled by default.

    Review and enable features such as:

    • Multi-Factor Authentication.

    • Account recovery options.

    • Login notifications.

    • Security alerts.

  6. Choose providers with strong security practices - When selecting online services, consider whether the provider:

    • Supports Multi-Factor Authentication.

    • Responds transparently to security incidents.

    • Provides strong privacy and security controls.

    • Has a good record of protecting customer information.


Donate

Your generosity makes our free support possible. Please consider giving today.

Without donations, we cannot keep our service free or provide help to the most vulnerable victims of cybercrime when they need it most. As a not-for-profit organisation, every donation goes directly towards keeping The Cyber Helpline up and running. Donate now and help us support victims of cybercrime.