Editorial : TransUnion security loopholes remain unplugged

THE security of the online service of TransUnion, who holds the credit information of over five million people in Hong Kong, was found to contain major flaws. TransUnion submitted a report to the Hong Kong Association of Banks (HKAB) six months after the flaws were exposed. However, the report was written in a slipshod manner and has been rejected by the HKAB. TransUnion's majority shareholder is a US‑based company. It is the sole consumer credit information service agency in Hong Kong. Since it holds the most sensitive financial information of Hong Kong citizens, it is obliged to strengthen privacy protection. However, TransUnion has failed to put forth any method to plug the security loopholes and reopen its online credit report service. What is even more shocking is that the report does not make a comment or draw a conclusion regarding the overall security situation. The government should strengthen its regulation of TransUnion and introduce competitors to prevent monopolies in the market.
Last year this newspaper identified a serious flaw in TransUnion's online procedures for obtaining data. A client whose identity was not ascertained could easily obtain personal credit data online. The security measures in place were unsophisticated and ridiculous. After the loopholes came to light, TransUnion suspended its online credit report service and apologised to the public at the Legislative Council.
In the investigation report submitted to the HKAB, TransUnion confirms that the risks of some of its online login procedures are "critical" and "high". However, it does not suggest any way to close the security loopholes. What is more shocking is that the report does not make a comment or draw a conclusion regarding the security measures and the overall security situation of TransUnion's online credit report service. A ridiculous error is also found in the report. An item for evaluation falls into different risk classifications in different chapters. Given the sloppiness and carelessness of the report, it is inevitable that the public is doubtful about TransUnion's intention to tackle its security loopholes.
The HKAB has rejected TransUnion's report, criticising it for being incomplete and having discrepancies. TransUnion has been asked to revise the report and provide a "full and professional" independent review. The crux of the matter is that TransUnion is not under the supervision of the Hong Kong Monetary Authority or the HKAB. The latter has made a number of requests to TransUnion, including enhancing the safety of its online system, improving the monitoring processes, and appointing an independent third party to assess the effectiveness of its remedial measures, etc. However, TransUnion may very well turn a deaf ear to these requests. Since it is the sole company that provides such kind of service in Hong Kong, the banks have to rely on it sometimes for credit information to make decisions on whether they should lend money to certain clients. In a monopolised market, there is nothing the bank can do if TransUnion deliberately thwarts the requests of the HKAB and does not cooperate.
Hong Kong is an international financial centre and TransUnion holds a large amount of sensitive credit and financial information of Hong Kong. The government should not regard the company simply as an average commercial entity. If the online security problems of TransUnion are not resolved properly soon, the government should intervene by exploring ways to strengthen supervision of the company. The government has the responsibility to ensure that sensitive financial information of Hong Kong residents will not fall into the hands of other people. All practical measures, including introducing competition into the market, should be considered to end the monopoly of an American‑based company on the personal credit information of Hong Kong.

Related Posts:

  • 銀公:環聯承諾提升系統防再洩密 銀公主席禤惠儀表示,保障市民私隱為底線。何耀勤攝 適中字型 較大字型 【本報訊】 去年底個人信貸評級資料庫環聯爆出保安漏洞,今日環聯首次就事件上立法會解畫。今年輪任為銀行公會主席的渣打香港區行政總裁禤惠儀指,社會關注網絡系統安全及私隱程度日增,事發後公會一… Read More
  • 【環聯洩私隱】信貸資料疑外洩 林鄭月娥接獲來信稱已採取補救 林鄭月娥接獲環聯來信稱已採取補救。資料圖片 載有全港540萬個市民信貸記錄的環聯資訊,被指存在嚴重保安漏洞,令客戶信貸資料有機會外洩。據悉,有人利用漏洞取得特首林鄭月娥的信貸資料,特首辦公室回應指已收到環聯來信,表示已採取補救措施加強保護。特首辦表示,環聯持有大量市民個人資料,有責任採取有效的保… Read More
  • 環聯是甚麼? 環聯載有逾500萬人借貸資料,包含個人資料、住址、信貸評級、信用卡額度、負債情況等。 適中字型 較大字型 香港信貸數據資料庫成立逾30年,環聯資訊(前稱:香港資信,CIS)於1982年由12間提供汽車及設備信貸融資的機構成立,當年僅涉車貸資料。自1985年擴展至收… Read More
  • 環聯信貸疑有嚴重漏洞 環聯:已凍結受影響賬戶 據明報報道,載有本港逾500萬人借貸資料的環聯資訊(TransUnion)現嚴重漏洞,記者發現只要憑目標人物的身份證號碼及公開資料,回答數條簡單問題,便能通過身份核證步驟。且以此方法取得公眾人物的信貸報告,內容包括其信貸評分、電話、地址、信貸帳戶號碼,和逾期還款等敏感資料。 相關新聞:【… Read More
  • 環聯暫停網上信貸報告查詢 環聯暫停網上信貸報告查詢 (蘋果日報) 2018年11月30日 【蘋果日報】環聯的信貸保安漏洞事件繼續發酵,公司昨宣佈,即時暫停香港所有網上消費者信貸報告查詢服務,直至另行通知。換句話說,現時不能再以個人身份透過網上查詢信貸報告,包括環聯官網和其他第三方合作平台。銀行界擔憂有不法之徒獲得他人… Read More