Editorial : TransUnion security loopholes remain unplugged

THE security of the online service of TransUnion, who holds the credit information of over five million people in Hong Kong, was found to contain major flaws. TransUnion submitted a report to the Hong Kong Association of Banks (HKAB) six months after the flaws were exposed. However, the report was written in a slipshod manner and has been rejected by the HKAB. TransUnion's majority shareholder is a US‑based company. It is the sole consumer credit information service agency in Hong Kong. Since it holds the most sensitive financial information of Hong Kong citizens, it is obliged to strengthen privacy protection. However, TransUnion has failed to put forth any method to plug the security loopholes and reopen its online credit report service. What is even more shocking is that the report does not make a comment or draw a conclusion regarding the overall security situation. The government should strengthen its regulation of TransUnion and introduce competitors to prevent monopolies in the market.
Last year this newspaper identified a serious flaw in TransUnion's online procedures for obtaining data. A client whose identity was not ascertained could easily obtain personal credit data online. The security measures in place were unsophisticated and ridiculous. After the loopholes came to light, TransUnion suspended its online credit report service and apologised to the public at the Legislative Council.
In the investigation report submitted to the HKAB, TransUnion confirms that the risks of some of its online login procedures are "critical" and "high". However, it does not suggest any way to close the security loopholes. What is more shocking is that the report does not make a comment or draw a conclusion regarding the security measures and the overall security situation of TransUnion's online credit report service. A ridiculous error is also found in the report. An item for evaluation falls into different risk classifications in different chapters. Given the sloppiness and carelessness of the report, it is inevitable that the public is doubtful about TransUnion's intention to tackle its security loopholes.
The HKAB has rejected TransUnion's report, criticising it for being incomplete and having discrepancies. TransUnion has been asked to revise the report and provide a "full and professional" independent review. The crux of the matter is that TransUnion is not under the supervision of the Hong Kong Monetary Authority or the HKAB. The latter has made a number of requests to TransUnion, including enhancing the safety of its online system, improving the monitoring processes, and appointing an independent third party to assess the effectiveness of its remedial measures, etc. However, TransUnion may very well turn a deaf ear to these requests. Since it is the sole company that provides such kind of service in Hong Kong, the banks have to rely on it sometimes for credit information to make decisions on whether they should lend money to certain clients. In a monopolised market, there is nothing the bank can do if TransUnion deliberately thwarts the requests of the HKAB and does not cooperate.
Hong Kong is an international financial centre and TransUnion holds a large amount of sensitive credit and financial information of Hong Kong. The government should not regard the company simply as an average commercial entity. If the online security problems of TransUnion are not resolved properly soon, the government should intervene by exploring ways to strengthen supervision of the company. The government has the responsibility to ensure that sensitive financial information of Hong Kong residents will not fall into the hands of other people. All practical measures, including introducing competition into the market, should be considered to end the monopoly of an American‑based company on the personal credit information of Hong Kong.

Related Posts:

  • 傳夥拍中銀拓信貸庫 諾華誠信撼環聯 銀行界冀引入競爭減成本 【本報訊】掌握本港逾500萬人借貸資料的資訊方案供應商環聯資訊(TransUnion),去年底爆出保安漏洞後,凸顯市場缺乏競爭的隱憂,由中銀信用卡前舵手蘇誠信創辦的諾華誠信(Nova Credit),前年底成立後亦加快發展。消息指諾華誠信最近與業界會晤,透露將與中銀香港(2388)簽訂客戶資料共… Read More
  • 港人平均持4.6張信用卡 環聯:貪圖開戶贈品 港人習慣以信用卡消費,平均每人有4.6張信用卡。環聯一項調查發現,雖然近九成受訪者表示他們經常還清卡數,但他們對信貸評級的認知不足,缺乏良好的理財習慣。 調查顯示,近七成受訪者清楚只繳付最低還款額會拉低信貸評級,約四成受訪者亦從來沒有查閱個人信貸報告。港人開立帳戶時以優惠及折… Read More
  • 諾華誠信 【豪言壯語】環聯倒下 誰來補上?   在經歷國泰洩露事件,然後電子錢包失竊,接著是PayMe帳戶被盜用,香港人已成驚弓之鳥。在這個時候,《明報》再投下一顆炸彈,揭露信貸資料庫「環聯」的安全漏洞。有趣的是,文章才刊登10分鐘,早已在金融界之間廣傳。 「環聯的競爭對手,可能是第一個『… Read More
  • 諾華誠信引6中小行 建跨境企業信貸庫 【明報專訊】本港的信貸資料庫業務長期由環聯所壟斷,但未來形勢將重大改變。中銀信用卡前總經理蘇誠信創立的「諾華誠信」,今年初引入6家中小型銀行、銀通與內地的中誠信為股東,銳意打造成涵蓋個人與企業的信貸資料庫,並利用科技為銀行偵察虛假交易與加強內部監控。諾華誠信行政總裁何佳意表示,希望盡快推出跨境工… Read More
  • 丘寧:環聯鬥諾華 銀公很頭痕 個幾月前,有傳媒踢爆香港環聯資訊有限公司(環聯)存在保安漏洞,包括行政長官在內的官員信貸資料外洩,周一立法會財經事務委員會更特意討論有關事件,反映政府高度關注的程度。正當市場聚焦應否修改私隱條例之際,近日有評論文章分析事件時提及,原來香港除了環聯之外,還有家叫諾華誠信的公司同樣提供個人與企業信貸… Read More