Supply chain ⛓ Supply Chain

Now:Pensions Third-Party Breach (December 2020)

📅 2020-12-01 🏢 Not disclosed
Primary Source ↗

Incident Details

Data breach hits 30,000 signed up to workplace pensions provider. Fraud worries as UK company Now:Pensions says ‘third-party contractor’ posted personal details of clients to online public forum. About 30,000 customers of Now:Pensions face an anxious Christmas after a serious data breach at the pensions provider led to their sensitive personal details being posted on the internet. In an email sent to affected customers, the workplace pensions firm warned that names, postal and email addresses, birth dates and National Insurance numbers all appeared in a public forum online.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Not disclosed
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2020-12-01 Breach occurred
  2. 2020-12-23 Publicly disclosed