DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Peoples Trust Company hacked; Bank arranges for credit alert flags on customers’ accounts for 6 years

Posted on November 3, 2013 by Dissent

Someone kindly alerted me to a breach involving Peoples Trust Company in Canada.  Here is the text of a notification letter they sent out, as provided by one of the recipients (hence, DataBreaches.net can assure its complete authenticity/accuracy):

October 25th, 2013

RE: Important Notice Regarding Your Personal Information

Dear First Name Last Name,

As is common with most Financial Institutions, and indeed most successful companies, Peoples Trust is constantly on guard against undesirable third parties gaining access to our systems and data, and is repeatedly required to repel unwanted incursions. Over the past 25 years we have successfully fended off all attempts to compromise our systems. However during the past week of October 7th, we became suspicious of a few events that might indicate a possible intrusion into a database on our website. This database was totally separate from our banking systems so no banking information, such as balances, account numbers, logins or passwords could be obtained. As a precautionary measure, we immediately removed all data from this area and enhanced identification procedures and daily processes in our Deposit Services area to monitor for unusual activity pending a full investigation. To date we have seen no suspicious activity.

We retained a forensic investigator to identify the nature of the problem, extent and source of a potential data compromise. On October 11, 2013, the forensic investigator confirmed that a database used to collect on-line application information on our website was compromised by unauthorized access originating in the Peoples Republic of China. None of our banking systems were infected.

The personal information that may have been accessed on this database includes customer name, address, telephone number, email address, date of birth and social insurance number. We can confirm with confidence that your financial information, account data and password information have not been compromised in any way. However this incident may still place some customers at risk for identity theft. We have informed the Police and Canada’s Privacy Commissioner, as well as the two major Canadian Credit bureau service providers. To mitigate the risk, Peoples Trust has arranged for a flag to be placed on your credit file which will alert companies accessing your credit information that your data may have been compromised and that lenders should take additional steps to verify your identity before transacting further. The notation will stay on your credit file for a period of 6 years unless you choose to have it removed.

It is not possible to verify the extent of access – or the amount of customer data that could possibly have been compromised – and we are hopeful the impact will be minimal, given the responses we’ve received from our customers to date (which has been limited to the receipt of a text message requesting a call to an inactive number).

Nothing is more important to Peoples Trust than the security of our customers’ personal information. In addition to the steps we have taken, we would like to recommend the following to protect yourself from risk of identity theft or fraud:

– If you receive emails or text messages in the days ahead purporting to be from Peoples Trust asking for account or any other information, please consider that email or text to be fraudulent, and contact us immediately at 1-855-286-8505. Peoples Trust does not solicit account information from customers by email or text.

– Never respond to any unsolicited requests for your banking or personal information.

– As a precautionary measure, we recommend you monitor your accounts for any unusual activity and report any irregularities to to Peoples Trust immediately at 1-855-286-8505.

– You obtain a free copy of your credit file which may be done by calling the following services: Equifax Canada (1-800-465-7166) or TransUnion Canada (1-800-663-9980) and requesting a printed copy be delivered to you by mail. You may also obtain further information on removing the alert by visiting their websites: http://www.equifax.ca or http://www.transunion.ca

If you have any questions about this incident, how it may affect you and the steps Peoples Trust is taking to protect you and your personal information, please call our special information line at1-855-286-8505. You can also contact Peoples Trust’s Privacy Officer:

Darren Kozol, Privacy Officer
14th Floor, 888 Dunsmuir St
Vancouver, BC
V6C 3K4
PH: 604-331-2238
@: [email protected]

Unfortunately, unauthorized privacy incursions are becoming more and more common all over the world. Peoples Trust will continue to take steps to safeguard your information with us. Moe information on personal information security and protecting yourself against identity theft is available from the Office of the Privacy Commissioner at http://www.priv.gc.ca . You should note that they provide a fact sheet on their website entitled “Identity Theft: What it is and what you can do about it” which may be of assistance to you in the present circumstances.

Peoples Trust deeply regrets that this occurred and is doing everything in our means to prevent an incident like this from happening again. Thank you for your understanding, and do not hesitate to call us if you have any questions or concerns.

Yours Sincerely,
Bill Moffatt
Chief Operations Officer
Peoples Trust Company

There is a lengthy discussion of the breach and the placement of the flags by customers here.


Related:

  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Toys “R” Us Canada customers notified of breach of personal information
  • Gatineau gymnastics centre warns members of possible data breach
  • Data breach in 42 Latvian municipalities: DVI imposes 300,000 euro fine on ZZ Dats
  • Kaufman County's data breach was their second one in three weeks
Category: Financial SectorHackNon-U.S.

Post navigation

← Hundreds of Australian Websites Attacked for #OpAustralia By Indonesian Hackers, Threats Made To Australia
Healthcare security standard launched to end data breach blunders →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.