[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzahtxwv9glie":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda488251bc","experian2020","Experian (South Africa) Data Breach","experian-south-africa","experian.co.za","2020-08-19T00:00:00.000Z","2020-09-01T23:39:52.000Z","2026-07-09T23:25:25.923Z","2026-07-18T23:50:30.258Z","Fraudulent data inquiry","https:\u002F\u002Fwww.experian.co.za\u002Ffraudulent-data-incident",[16,18,19,20],"https:\u002F\u002Fwww.experian.co.za\u002Ffraudulent-data-incident\u002Ffaqs","https:\u002F\u002Finforegulator.org.za\u002Fwp-content\u002Fuploads\u002F2020\u002F07\u002Fms-20211027-Experian.pdf","https:\u002F\u002Fwww.experianplc.com\u002Fnewsroom\u002Fpress-releases\u002F2020\u002Fexperian-south-africa-curtails-fraud-incident",1284637,"known",null,"unknown","Critical",[27,28,29,30,31,32],"Email addresses","Employers","Government issued IDs","Names","Occupations","Phone numbers","\u003Cp>\u003Cstrong>Experian (South Africa) data breach\u003C\u002Fstrong> is related to the fraudulent data request incident that Experian South Africa experienced in 2020 with a person pretending to be a legitimate customer. This incident should not be described in the classic sense as systems being hacked or databases being directly accessed; according to official statements, the person acted as if they were a legitimate company executive to obtain data services, and Experian shared contact and employment-focused information in response to this request. The number of accounts in the records containing verifiable emails is 1,284,637. The broader scope of the incident has additionally been reported as approximately 24 million South African individuals and 793,749 businesses.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The data classes verified in this record are email addresses, employer information, official identification information, names, professional information, and phone numbers. Email and phone information directly increase the risk of contact; name, profession, and employer information can make messages appear more realistic. Records with official ID numbers or context involving identity verification increase the risk of identity authentication and fraud if matched with other datasets. Therefore, the incident should not be seen merely as marketing data or a simple contact list.\u003C\u002Fp>\n\u003Cp>Employer and occupational information can lead to targeting based on the institution the person works for, their position, or professional environment. Scenarios such as fake job offers, insurance proposals, credit products, payroll updates, employee verification, or bank security checks can become more convincing. When a phone number and email address are found together, the attacker may first send a message and then call, trying to build trust. This record carries a social engineering risk based on identity, contact, and employment profile rather than a password-focused account takeover incident.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number of queryable accounts used in this record is 1,284,637; because only a portion of the records in the larger dataset contains an email address. Although the overall scope of the incident has been reported as approximately 24 million individuals and 793,749 businesses, this number should not be confused with the number of records that can be queried via email. The official statements also mention that bank account numbers were shared for 24,838 businesses; this information should not be confused with individual consumer data categories. On the individual record side, verified fields are limited to email, employer, official ID, name, occupation, and phone categories.\u003C\u002Fp>\n\u003Cp>The timeline of the incident should also be clearly separated. The sharing of information with the fraudulent person took place on May 24 and 27, 2020, Experian South Africa detected the incident on July 22, 2020, and the public announcement was made on August 19, 2020. This record date is kept according to August 19, 2020, which is the date announced to the public and used in breach record systems. It should not be claimed in the statement that the systems were directly hacked, that all financial data was shared for individuals, or that passwords were leaked; such a claim would go beyond the verified scope.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>In the highest risk group in South Africa, there are individuals included in the Experian data ecosystem regarding credit, communication, employment, or identity verification processes. When a person's name, phone, email, employer, and occupation information are found together, attackers can prepare messages that appear consistent with the person's professional life. Payroll, insurance, credit, personnel verification, or work phone update messages that appear to come from the workplace become more convincing with this data combination. The context of official identity information, when combined with information from other sources, can also increase the risk of account opening or verification.\u003C\u002Fp>\n\u003Cp>The risk is different for businesses. Company registration information, business contact details, credit profile, and bank account number fields for certain businesses can be used in scenarios such as fake supplier, invoice, credit application, or payment redirection. Therefore, the issue is not only a matter for individual consumers; company officials, finance teams, business development teams, and customer communication teams can also be targeted. Individuals matching the registration should pay particular attention to messages coming through employer or professional information.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If you see a match, first carefully evaluate credit, insurance, employer verification, account update, or identity check requests received via email and phone. The caller should not be considered trustworthy just because they know your name, employer, or profession. Regularly monitor your credit report and identity verification activities; if you notice unusual credit inquiries, new account openings, or changes in contact information, contact the relevant institution directly through the official channel you have established.\u003C\u002Fp>\n\u003Cp>On the business side, the finance team should be informed about the risk of fake invoices and payment redirection related to bank account numbers or company profiles. Changes in payment information should not be approved through a single channel, and a second verification channel should be used. Individual users should use strong passwords and multi-factor authentication for their email accounts and should not respond to requests for sharing one-time codes sent via phone. Forms requesting identity or business information should be verified by manually typing the institution's domain name, not through a link.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident shows that the communication and employment data held in the data broker and credit bureau ecosystem can create long-term risks. Users should protect themselves with regular credit report checks, unusual credit inquiry alerts, and identity monitoring services. When employer and occupational information changes, it is difficult to track where records remaining in old profiles are used; therefore, the purpose and retention period of every institution requesting personal information should be questioned. Reducing unnecessary phone and email sharing lowers the risk of targeted messages in the long term.\u003C\u002Fp>\n\u003Cp>From the perspective of institutions, the incident shows that customer acceptance and data request verification processes are as important as technical security. Verification of company officials, purpose limitation, data minimization, additional consent, and monitoring of unusual requests should be strengthened against individuals acting as legitimate customers. In the sharing of business data, bank account fields should also be protected, and in personal data, official identity and employment information should be separated as much as possible. On the user side, keeping credit alerts active and being cautious with external contacts provides lasting protection.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Matching with the Experian (South Africa) record indicates that your email address is included in the dataset associated with this incident. This result does not mean that every field in the entire dataset pertains to you; however, you should take seriously the possibility of being targeted through email, phone, ID, employer, or occupation information. Check your credit report, monitor unexpected credit inquiries, verify messages appearing to be from an employer or financial institution, and be cautious of identity verification pressure over the phone.\u003C\u002Fp>\n\u003Cp>This record has been prepared to accurately describe the Experian South Africa incident: while the overall incident may affect approximately 24 million individuals and 793,749 businesses, the number of queryable records containing email addresses is 1,284,637. The incident should be evaluated as fraudulent data requests rather than a system breach. User actions; monitoring identity and credit activity, being cautious against employer\u002Fprofession-themed social engineering messages, enhancing email and phone security, and, on the business side, verifying payment information changes through multiple channels.\u003C\u002Fp>","","Experian (South Africa) Data Breach (1.3 Million Reported Records)","Experian (South Africa) Data Breach. 1.3 Million reported records were reported. Reported data: Email addresses, Employers, Government issued IDs. Review the…","\u002Fuploads\u002Flogo\u002Fexperian2020.webp",false,{"name":40,"sector":41,"country":42,"website":10,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":23},"Experian South Africa","Credit reporting","South Africa"]