Kiwis who use the investment platform Hatch have been warned their personal information may have been exposed in a cybersecurity incident.
In an email to investors, the New Zealand platform said its US brokerage partner, DriveWealth, had been hit by the breach earlier this month.
It said an unauthorised party accessed data held on DriveWealth's system on September 4 and 5. Some of the data related to customers who invested through Hatch.
Hatch said the breach may have exposed investors' names, addresses, phone numbers, and email addresses. No passwords were compromised.
The breach may also have exposed investor profile information, such as income range and net asset range, as well as cash balance and portfolio value.
Hatch allows Kiwis to invest in US share markets like the New York Stock Exchange and the Nasdaq. It uses DriveWealth as its US-regulated broker to access US markets.
It said DriveWealth was "required to collect and store certain personal information so you can access and trade on exchanges such as the NYSE and NASDAQ".
The company warned the information could be used to make fraudulent emails, text messages or phone calls more convincing.
"We advise customers take extra care with unexpected contact about Hatch, DriveWealth or their investments."
Some with closed Hatch accounts may have also had their information exposed, as US regulations required DriveWealth to retain certain information for a period of time.
Investors were told their login details were not affected because that data was held in Hatch's own system, which was not compromised.
"DriveWealth is confident that no unauthorised transactions were made and your holdings were not affected by the incident.
It said Hatch customers did not need to change their passwords because of the incident.
Hatch said DriveWealth had investigated the incident with the help of independent cybersecurity experts.
"It has advised us that it has not identified an ongoing threat to its systems and has strengthened its security controls following the incident.
"We are continuing to work closely with DriveWealth as its investigation progresses and are engaging with the relevant authorities."
Hatch said it had notified police and the National Cyber Security Centre.
It urged investors never to share passwords or two-factor authenticator codes, to be cautious about unexpected or urgent requests, not to click links in suspicious messages, and to protect email accounts.
"If customers receive suspicious contact claiming to be from Hatch, or notice anything unexpected in your account, they should contact us."
The morning's headlines in 90 seconds, including National's attack ad backfires, and a terrifying collision at sea (Source: Breakfast)






















SHARE ME