Tag Archives | Sage

Cluley 250 thumb

Following data breach, Sage employee arrested at Heathrow airport

City of London Police arrested a 32-year-old woman at Heathrow airport yesterday on "suspicion of conspiracy to defraud".

According to police, the arrested woman is a current employee of Sage.

Sage made the headlines earlier this week after the online accounting and payroll company announced it had suffered a data breach, putting the details of approximately 280 UK and Irish companies at risk.

Sage described this as a "small number" of their customers. And it is a small percentage, considering over half a million British businesses are thought to be using Sage's payroll software.

But, of course, that's little consolation if you're one of the customers whose data was put at risk by the breach. And the number alone doesn't tell us anything about the size of the companies affected, or how many employees of those companies could also potentially have had their identities and financial details put in danger.

Police say that the woman arrested at Heathrow airport has been released on bail.

Sage said that an internal login had been used to access the sensitive information.

It's worth underlining that the woman arrested has not been charged with any offence, let alone convicted... but this might be a timely reminder for all businesses to not focus solely on external attackers over the internet but recognise that there can also be considerable dangers posed by insiders if your workforce turns rogue.

Cluley 250 thumb

Sage suffers data breach, putting details of UK and Irish businesses at risk

Online accounting software company Sage has suffered a data breach, putting the details of a "small number" of its UK and Irish business customers at risk.

As the company briefly noted on its website:

We believe there has been some unauthorised access using an internal login to the data of a small number of our UK customers so we are working closely with the authorities to investigate the situation.

Our customers are always our first priority so we are communicating directly with those who may be affected and giving guidance on measures they can take to protect their security.

If you have any concerns at all, you can reach us on the following contact details:

The dedicated helpline number is 0845 145 3345 - please leave a message with your details and we will get back to you as soon as we can. You can also get in touch with us by emailing us at customercontact@sage.com.

Richard De Vere of the AntiSocial Engineer posted this weekend providing further information and commentary, saying that the "personal details and bank account information for employees of as many as 300 large UK companies may have been compromised."

De Vere went on to warn of the risks of insider threats to all businesses:

"An insider threat can strike any business, Sage have an industry leading product that is secure as many cloud providers are these days. The problem isn't with Sage, but in how companies manage these insider risks."

Sage says it has been contacting affected customers.