HomeSecurityFortnum Private Wealth exposed clients to cyber threats

Fortnum Private Wealth exposed clients to cyber threats

Australia's financial regulator has brought legal action against financial services firm Fortnum Private Wealth, accusing it of exposing its clients to cyber threats.

See also: Sundar Pichai: AI can help strengthen defense against cyber threats

Fortnum Private Wealth cyber threats

The Australian Securities and Investments Commission (ASIC) filed a lawsuit against the financial advisory firm in the Supreme Court of New South Wales on July 21.

ASIC alleges that Fortnum Private Wealth did not have adequate policies, frameworks, systems and controls in place to address cybersecurity risks. The Commission alleges that these deficiencies contributed to a number of Fortnum clients and authorised representatives experiencing cyberattacks

One of the incidents led to a serious data breach of over 200GB, involving up to 9,828 customers in September 2022. This confidential information was later published on the dark web.

See also: Microsoft: Free cybersecurity program in Europe

In many cases, a malicious actor gained access to authorized representative (AR) email accounts, which they used to send phishing emails to customers.

Fortnum Private Wealth exposed clients to cyber threats
Fortnum Private Wealth exposed clients to cyber threats

Most of these incidents occurred after Fortnum introduced a specific cybersecurity policy in April 2021. ASIC argues that the policy was not an adequate response to managing cybersecurity risks, especially for a financial services company that handles highly sensitive customer data.

This policy was revised in May 2023. ASIC stated that it is seeking an injunction acknowledging Fortnum's failures, as well as imposing a financial penalty on the company.

In a statement published on Financial Newswire, Fortnum's chief executive, Matt Brown, said the company "categorically refutes" ASIC's claim that it failed to implement appropriate cybersecurity controls.

See also: NCSC: Security guidance following attacks on M&S, Harrods, Co-op

It is also noteworthy that even after the implementation of a policy in 2021, its ineffective implementation was demonstrated in practice by repeated incidents. This shows that having a policy in place alone is not enough — substantial implementation, technical safeguards and active monitoring are also required. Such cases highlight the need for regulatory oversight (such as that of ASIC), but also for corporate responsibility towards customers.

Source: infosecurity-magazine

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS