Supply chain [SC] Supply Chain

Nedbank Third-Party Breach (February 2020)

2020-02-01 [vendor] Computer Facilities (Pty) Ltd
Primary Source ↗

Incident Details

Nedbank says 1.7 million customers impacted by breach at third-party provider. Hacker(s) believed to have exploited a vulnerability to breach Nedbank’s marketing contractor. Nedbank, one of the biggest banks in the South Africa region, has disclosed a security incident yesterday that impacted the personal details of 1.7 million users. The bank says the breach occurred at Computer Facilities (Pty) Ltd, a South African company the bank was using to send out marketing and promotional campaigns. Third-party company: Computer Facilities (Pty) Ltd.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Computer Facilities (Pty) Ltd
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2020-02-01 Breach occurred
  2. 2020-02-14 Publicly disclosed