ADVERTISEMENT

900,000 customers at risk after Cebuana Lhuillier data breach

Published Jan 19, 2019 12:00 am
By Madelaine Miraflor Diversified financial services firm Cebuana Lhuillier, known nationwide for its remittance services, suffered a nation­wide data breach that puts at risk all the personal data of the company’s 900,000 customers. (MANILA BULLETIN) (MANILA BULLETIN) Cebuana Lhuillier’s Data Privacy Officer sent a “notice” to all its clients via email Saturday morning, January 19, informing them of the data breach. Richard Villaseran, AVP for Corporate Communications, later on said in a state­ment that the data breach exposed the personal information of around 900,000 of its clients. Some of these information in­cluded birthdays, addresses, and sources of income. National Privacy Commissioner (NPC) Raymund Enriquez Liboro said the inci­dent is now under investigation. The data privacy watchdog also gave Cebuana Lhuiller 72 hours from discovery of a data breach within which to report the same to the NPC and the affected data subjects. “The data subject notification must be done individually and not further expose the data subject to more harm,” Liboro stressed. According to Liboro, Cebuana Lhuillier representatives reported Fri­day, January 18, to the NPC, seeking assistance regarding the data breach involving their email server. At the meeting, they committed to submit a more detailed report regarding the data breach. “Cebuana Lhuiller informed us that it has engaged the services of a third party information security service provider to handle their mitigation and response to this incident. We await further details as to scope and severity of the breach,” said Liboro. Aside from birthday, address, and source of income, data at stake include email addresses and mobile numbers. “We are writing to inform you of a security incident which may have af­fected your personal data stored in one of our email marketing tool servers,” the company told its customers. The company said it detected on January 15 attempts to use one of its email servers as a relay to send out spam to other domains. “Follow-up investigation resulted in the discovery of unauthorized download­ing of contact lists used as recipients for email campaigns. These unauthorized downloads took place on August 5, 8, and 12, 2018,” Cebuana Lhuillier said. “Upon discovery, remedial actions were taken to reduce the harm. The server was immediately disconnected from the network after confirmation of breach,” it added. Cebuana Lhuillier has 2,500 branches nationwide. It operates businesses dealing with financial services such as pawning, remittance, microinsurance, and business-to-business micro loan solutions. The Cebuana Lhuiller data breach occurred days after another major data breach supposedly took place at the De­partment of Foreign Affairs (DFA), which raised concerns about possible identity theft and that personal data taken from the agency may be used to manipulate the automated 2019 senatorial polls.
ADVERTISEMENT
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function initializeAllSwipers() { // Get all hidden inputs with cms_article_id document.querySelectorAll('[id^="cms_article_id_"]').forEach(function (input) { const cmsArticleId = input.value; const articleSelector = '#article-' + cmsArticleId + ' .body_images'; const swiperElement = document.querySelector(articleSelector); if (swiperElement && !swiperElement.classList.contains('swiper-initialized')) { new Swiper(articleSelector, { loop: true, pagination: false, navigation: { nextEl: '#article-' + cmsArticleId + ' .swiper-button-next', prevEl: '#article-' + cmsArticleId + ' .swiper-button-prev', }, }); } }); } setTimeout(initializeAllSwipers, 3000); const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); let article = entry.target; // Extract metadata const author = article.querySelector('.author-section').textContent.replace('By', '').trim(); const section = article.querySelector('.section-info ').textContent.replace(' ', ' '); const title = article.querySelector('.article-title h1').textContent; // Parse URL for Chartbeat path format const parsedUrl = new URL(newUrl, window.location.origin); const cleanUrl = parsedUrl.host + parsedUrl.pathname; // Update Chartbeat configuration if (typeof window._sf_async_config !== 'undefined') { window._sf_async_config.path = cleanUrl; window._sf_async_config.sections = section; window._sf_async_config.authors = author; } // Track virtual page view with Chartbeat if (typeof pSUPERFLY !== 'undefined' && typeof pSUPERFLY.virtualPage === 'function') { try { pSUPERFLY.virtualPage({ path: cleanUrl, title: title, sections: section, authors: author }); } catch (error) { console.error('ping error', error); } } // Optional: Update document title if (title && title !== document.title) { document.title = title; } } } }); }, { threshold: 0.1 } ); function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // Offset values const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } const sentinel = document.getElementById("load-more-sentinel"); if (!sentinel) { console.log("Sentinel element not found."); return; } function isSentinelVisible() { const rect = sentinel.getBoundingClientRect(); return ( rect.top < window.innerHeight && rect.bottom >= 0 ); } function onScroll() { if (isLoading) return; if (isSentinelVisible()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { let article = document.querySelector('#widget_1690 > div:nth-last-of-type(2) article'); intersectionObserver.observe(article) loadCount++; }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; }); } } window.addEventListener("scroll", onScroll); });

Sign up by email to receive news.