ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Norwich Union Life fined £1.26m for data loss

Tom Espiner ZDNet.co.uk

Published: 17 Dec 2007 13:31 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Financial Services Authority has fined Norwich Union Life £1.26m for failing to manage customer data adequately, resulting in financial crimes such as identity theft being committed against its customers.

Aviva PLC, of which Norwich Union Life is a subsidiary, issued a statement on Monday apologising for the fraud. It admitted that, "due to some weaknesses in internal controls, 74 policies were fraudulently surrendered and 558 other customers' policies were placed at risk" over the course of 2006.

According to the FSA, weaknesses in Norwich Union Life's systems and controls allowed fraudsters to use publicly available information, including names and dates of birth, to impersonate customers and obtain sensitive customer details from its call centres. Also, in some cases they were able to ask for confidential customer records such as addresses and bank account details to be altered.

"The fraudsters used the information to request the surrender of 74 customers' policies [resulting in losses] totalling £3.3 million in 2006," said an FSA statement.

The FSA severely criticised Norwich Union Life, saying that it had failed its customers.

"Norwich Union Life let down its customers by not taking reasonable steps to keep their personal and financial information safe and secure," said Margaret Cole, the FSA's director of enforcement. "It is vital that firms have robust systems and controls in place to make sure that customers' details do not fall into the wrong hands. Firms must also frequently review their controls to tackle the growing threat of identity theft."

Norwich Union Life apologised, saying the fraud was unacceptable. The financial services company blamed "organised fraud" for the losses to its customers.

"We are sorry that this situation arose and apologised to the affected customers when this happened," said Mark Hodges, chief executive of Norwich Union Life. "We have extensive procedures in place to protect our customers but in this instance weaknesses were exploited and we were the target of organised fraud. Whilst the number of customers affected is very small compared to the number of policies we manage overall, any breach in customer confidentiality is clearly unacceptable."

Calling the breaches that led to the fine "a perfect example of trusted organisations not placing enough importance on managing personal data", database security company Secerno said the recent spate of public- and private-sector data-loss incidents could shake consumer confidence.

"Breaches such as the HMRC's loss of two discs affected 25 million people, while Leeds Building Society recently lost sensitive data relating to workers' payslips, and this month, the DVLA compromised 6,000 drivers after losing their sensitive information," said Paul Davie, founder of Secerno, on Monday. "Consumers and credit-card companies will no longer tolerate what have now become exceedingly routine data-loss incidents."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
10 out of 10 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Application Support Team Lead - Support Analyst - East Midlands

Ensures compliance with IT Service Management procedures for incidents, change and release and prepares performance management information for the ...

Top tier Investment Bank seeks Equity Finance Trade Support Analyst.

Understands regulatory requirements and company policies. Understands the lifecycle of a securities trade, and the following equity processes: ...

Implementation Engineer - Unix / Servers - London

Ensuring there are documented processes within the teams for the smooth running of the services -Provide troubleshooting and specialist support to ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment