Iress says cyber breach was limited to small number of clients

2 July 2024
| By Keith Ford |
image
image
expand image

In a statement to the ASX, Iress said it has concluded its internal investigation into the unauthorised access of Iress’ user space on GitHub first announced in May.

The breach impacted OneVue's managed funds administration, platform, and superannuation division.

While at the time, Iress said “there is no evidence that client data has been compromised”, it has now confirmed that some data had been accessed. 

“The investigation has found no evidence of unauthorised access to Iress’ production environment, software or client data other than a limited portion of Iress’ OneVue production environment,” Iress said in an ASX listing. 

“This environment primarily contained information of a technical nature such as metadata, blank questionnaires and test files.

“Within the test files, Iress also identified a limited amount of personal information relating to 20 individuals who were employees of OneVue and its clients, and had entered their personal information for testing purposes.”

Iress added that each of these individuals has been contacted directly about the incident and provided with “appropriate guidance and support”.

The firm said that it has engaged specialist cyber incident and forensic technology providers to assist in response to the incident.

Iress has again noted that it is aware of statements made by the alleged threat actor regarding publishing source code taken from Iress’ GitHub user space, which it had previously said “do not align with the investigations made by Iress to date”.

“Iress confirms that it does not rely on the secrecy of its code as a security measure and has continued to take steps to reinforce security controls to protect its software and systems,” Iress said on Tuesday morning.

“Iress has maintained regular service to clients throughout this incident and thanks its clients for their patience and support as we have worked to resolve this matter.”

GitHub is a third-party code repository platform that manages software code before it goes live in production on a separate platform.

In May, the firm stressed that “Iress does not store client information on GitHub”.

“Iress restricted access to GitHub immediately upon discovery and commenced a rapid investigation,” it said at the time.

“There is no evidence that client data has been compromised as a result of this issue. There is also no evidence that Iress’ production or client software has been compromised.”

Read more about:

AUTHOR

Add new comment

The content of this field is kept private and will not be shown publicly.

Recommended for you

sub-bgsidebar subscription

Never miss the latest developments in Super Review! Anytime, Anywhere!

Grant Banner

From my perspective, 40- 50% of people are likely going to be deeply unhappy about how long they actually live. ...

6 months 1 week ago
Kevin Gorman

Super director remuneration ...

6 months 2 weeks ago
Anthony Asher

No doubt true, but most of it is still because over 45’s have been upgrading their houses with 30 year mortgages. Money ...

6 months 2 weeks ago

The software firm has completed its investigation of the breach to its GitHub user space in May....

9 hours 57 minutes hence

A recent pulse check by the regulators has raised concerns about trustees’ lack of progress in tracking the success of their RIC strategies....

16 minutes 30 seconds ago

Having led the fund’s advice firm for almost five years and through multiple mergers, Sarah Forman has announced her intention to leave the $170 billion fund. ...

23 hours hence

TOP PERFORMING FUNDS

ACS FIXED INT - AUSTRALIA/GLOBAL BOND