Following this month's severe storm, Vector has been made aware of a API vulnerability in its Outage App. This has allowed users with an understanding of web applications to identify the API vulnerability and potentially exploit it to see information about other app users.

After investigation, we believe as many as 24,000 app users may have had their name, phone number and address details accessed through the vulnerability. We will be contacting those customers who may have had their data compromised over the next few days.

Please note no financial or banking information was held in the app, and the potential data breach was contained solely to information provided by customers to the app. The security of the Vector website, financial or electricity network systems has not been affected.

This data breach comes as we are working to significantly improve our customers' information experience during an outage, which was a clear problem following a recent storm.

We have taken the immediate step of disabling the Vector Outage app and withdrawn all customer records which were breached.

The app will remain disabled until we have total confidence our customers' data remains secure while using it.

The app has proven to be a popular and extremely effective way of providing customers with individualised information about outages affecting them. It will now be completely rebuilt to manage the dual issues of demand during large outages as well as ensuring even higher levels of data security. In the meantime, while the app is being rebuilt, any customers who need to report an outage should call 0508 VECTOR.

We ask our customers to be extra vigilant if they receive any unsolicited communication from anyone purporting to be from Vector.

Attachments

  • Original document
  • Permalink

Disclaimer

Vector Limited published this content on 26 April 2018 and is solely responsible for the information contained herein. Distributed by Public, unedited and unaltered, on 26 April 2018 05:58:03 UTC