270,000 customers advised not to worry but also to watch out for odd transactions and ponder password refresh
Payday lender Wonga has advised 270,000 customers of a data breach and offered inconsistent advice about the severity of the incident and how to respond.
An “incident FAQ” on the company's site says “We believe there may have been illegal and unauthorized access to the personal data of some of our customers.” The Reg understands 270,000 customers are potentially at risk, 245,000 of them in the UK.
Wonga says the data that parties unknown have accessed “may have included one or more of the following: name, e-mail address, home address, phone number, the last four digits of your card number (but not the whole number) and/or your bank account number and sort code.”
The FAQ offers contradictory advice on the incident, offering assurances that “We believe that your account is secure and you do not need to take any action" but also says “if you are concerned you should change your account password. We also recommend that you look out for any unusual activity across any bank accounts and online portals.”
The FAQ, and a letter sent to affected customers, also offers the following advice:
Exercise vigilance: Beware of scammers or unusual online activity. Be cautious of anyone who calls you and asks you to disclose any personal information regardless of where they say they are from. If this happens, we recommend that you hang up.
The Register has asked Wonga to clarify why customers need to keep an eye on “unusual activity” if their accounts remain secure and why they might experience inbound scam calls at this time.
Wonga says it is informing customers' banks of the situation, to help them detect any fraud.
The FAQ also asks the question “How did this happen in the first place and what measures are you taking to ensure that this does not re-occur?” and offers the following as a response:
Wonga charges annual interest rates of 1,509 per cent (yes, one thousand five hundred and nine per cent) for short-term loans designed to tide people over until payday. The company justifies its interest rates on grounds of convenience and value.
The PR people have made contact again hours after this article was published:
"Wonga is urgently investigating illegal and unauthorized access to the personal data of some of its customers in the UK and Poland. We are working closely with authorities and we are in the process of informing affected customers. We sincerely apologies for the inconvenience caused." ®