Top storiesNew ZealandPoliticsBusinessEntertainmentSportsWorld

Nib job applicants also at risk of the Page Up data breach

Tuesday, 19 June 2018

Nib NZ chief executive Rob Hennin says the company was made aware two weeks ago of a data security incident and has suspended its use of Page Up.
Nib NZ chief executive Rob Hennin says the company was made aware two weeks ago of a data security incident and has suspended its use of Page Up.

Health insurer Nib has suspended use of third-party e-recruitment platform PageUp following news job applicants' data was hacked.

Nib NZ chief executive Rob Hennin said the company was made aware two weeks ago of a data security incident and had been using PageUp since 2016. He said customer information had not been affected by the hack.

PageUp, which has 2.6 million users in 190 countries, confirmed its client data had been accessed by 'unauthorised persons' in a malware attack on May 23.

Sydney-based PageUp said on its website job applicants', employees' and former employees' names, email and physical addresses, phone numbers, biographical details such as date of birth, gender, country of residence, and employment details might have been compromised.

READ MORE:

Job seeker 'horrified' after recruitment website PageUp data breach threatens New Zealand applicants

Australian online recruitment organisation PageUp was hacked late last month, compromising some New Zealand job applicants personal data.
Australian online recruitment organisation PageUp was hacked late last month, compromising some New Zealand job applicants personal data.

Over half of Kiwis more worried about privacy online than two years ago

Thousands of 'vulnerable' customers' private data shared by Vector app

But no employment contracts, applicant resumes, tax file numbers, credit card information or bank account information were affected.

PageUp said the hack had been eradicated and cybersecurity professionals were reviewing its systems to improve security.

Associate professor of information security at Auckland University Lech Janczewski​ said there wasn't much applicants using online recruitment platforms could do, but in this particular breach, people could take comfort in knowing most of the information hacked was publicly available, anyway.

'For the most part it is a big storm in a tea cup, because if you search anyone up you will get all that information anyway,' Janczewski said.

'The new laws in Europe [General Data Protection Regulation] have greater protection of personal information as companies could face fined in the millions for data breaches. But there's not much a job applicant can do, if you are applying for a job online you are exposing yourself to that risk, so it's the website user's responsibility.'

Janczewski said internet users must be wary of clicking on links and attachments sent via email from unknown individuals and avoid using the same password for all websites.

Travel and adventure apparel store Kathmandu emailed job applicants to warn them of a possible privacy breach on Monday night.
Travel and adventure apparel store Kathmandu emailed job applicants to warn them of a possible privacy breach on Monday night.

Building company Downer has also disabled its recruitment database as a result of the PageUp data breach.

Publishing group Bauer Media and insurance company Zurich have also been contacted.  

 On Monday retail company Kathmandu and Australian airline Jetstar emailed job applicants to advise their privacy may have been breached. 

Neither company had been advised of any specific breach of data provided by Jetstar or Kathmandu job candidates, the emails said. 

'Whilst we are still waiting for a response from PageUp to confirm, in relation to Kathmandu job applicants, the specific data and specific individuals impacted, (amongst other information requests) we are contacting all individuals who could have been affected through applying for a job at Kathmandu,' Kathmandu's email said. 

However, both Kathmandu and Jetstar urged people who had applied for jobs to change their passwords and check there had been no unusual activity concerning their personal information. 

'We wanted to let you know what has happened so that you may take additional steps you deem appropriate to protect your privacy,' Jetstar said. 

Kathmandu used PageUp between 2015 and May 2018.

Jetstar said PageUp 'formerly' provided IT services used in their recruitment process and it now uses another e-recruitment website, Workday.

Earlier this year, major Australian universities, AusPost, Coles, Telstra, Commonwealth Bank, Lindt, Aldi, NAB, Medibank and the Reserve Bank of Australia were all affected, the Sydney Morning Herald reported.

The breach was being investigated by the Australian government's Cyber Security Centre.