Standard Bank employee copied client data to an unprotected personal device
- Organization
- Standard Bank
- Exploit
- Malicious Insider
- Industry
- Banking
Standard Bank confirmed on November 7, 2024 that client information had been exposed after an employee with authorized access copied it onto an unprotected personal device. The South African bank said the action broke its internal information security rules and that the case was picked up through its own monitoring processes rather than reported by an outside party.
The bank described the exposure as limited personal and financial information belonging to a limited number of clients in South Africa, and did not publish a figure. It said it does not keep or store client passwords or PINs, so those were not part of the incident, and that its banking systems themselves remained secure.
Affected clients were contacted directly by letter, and the bank said customers who had not heard from it were not caught up in the incident. Standard Bank notified the Information Regulator and other authorities as required by the Protection of Personal Information Act.
A disciplinary process was opened against the employee, which the bank said would be handled in line with South African labour law and data protection requirements, including the Labour Relations Act. Standard Bank added that it was reviewing and strengthening the way staff handle client data.