
Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account
An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.
Ontario
British Columbia
Alberta
Saskatchewan
Manitoba
Quebec
Nova Scotia
New Brunswick
Prince Edward Island
Newfoundland and Labrador
Yukon
Northwest Territories
Nunavut