blueday Posted October 7, 2020 Posted October 7, 2020 A school has had this email from Wisepay today: Data Security Incident – WisePay Platform We are writing to confirm the details we know so far about a security incident that has affected the WisePay Platform. As you will be aware, the website is currently offline. On Monday, 5 October 2020, we became aware of a cyberattack that appears to be a URL manipulation that spoofed the SagePay payment page. We immediately engaged a leading cybersecurity forensic agency and we will provide any required notifications of their investigation, together with specific details of affected transactions and individuals who attempted to make payments during this period. We understand the incident began to adversely affect the website on 2 October 2020. On 5 October 2020, we spoke to Simon Andrews of the Information Commissioner’s Office and filed a notice providing all the details of the incident we know at this time. We are providing this notification to you as our valued customer and in accordance with our obligations as a data processor. Please let us know if you have any questions. We will provide more detailed information in a prompt manner as soon as we are able to do so, with our investigations being underway. 2
Linfit Posted October 7, 2020 Posted October 7, 2020 Yep. we have had the same e-mail. Website has been offline since at least Monday - maybe sooner but we didn't notice over the weekend. No further info as yet. Not good - this is on top of an issue they had with their sync system at the start of the year that meant that new starter information could not be uploaded to them - it took over a week for all our Year 7's to appear.
blueday Posted October 7, 2020 Author Posted October 7, 2020 I'm assuming that apart from perhaps forwarding the email to parents, schools don't have to take any official actions for reporting this to the ICO themselves? Although Wisepay is a data processor in terms of information passed over, wouldn't they be the data controller for any transaction data entered on their website, which this presumably relates to?
Linfit Posted October 7, 2020 Posted October 7, 2020 (edited) I think thats correct - I would expect them to let us know if any of our parents accounts had been compromised and then we in turn would have to let the parents know. We cannot be the data controller for the credit card info and transactions as that data does not pass through our systems and we have literally "no control" over it. We will need to let all the parents know that there is a potential risk, but just debating here exactly how to phrase that - after all, there is nothing the parents can do about it at the moment as the site is offline. Edited October 7, 2020 by Linfit
enjay Posted October 7, 2020 Posted October 7, 2020 Curiously, WisePay have taken the whole system offline, not just the payment bit. Parents can't see their child's catering balance or purchase history, they can't view the payment status of any trips, and we can't email parents about any of this because we use WiseMail. This is the second WisePay issue this term (!) so we're currently reviewing alternative suppliers.
Linfit Posted October 7, 2020 Posted October 7, 2020 Yup, just checked and our data uplink from SIMS this morning failed - the endpoint has timed out, so looks like everything public facing is offline.
enjay Posted October 7, 2020 Posted October 7, 2020 We have enabled overdrafts on the tills so students won't get turned away, and the money will be taken when the parents next top up. Of course, at some point the message will get out there is free food available, but we're keeping an eye on the number of students who are in debt and by how much - hopefully this won't get abused too much, if it does we'll be sending WisePay the bill! We have manually emailed the parents saying we're aware of the issue, and we've put a notice on our website and social media. Is there anything else we can sensibly do while we ride this out? 1
JJonas Posted October 7, 2020 Posted October 7, 2020 I don't believe we have received this email. I am emailing Wisepay now.
hglyde Posted October 7, 2020 Posted October 7, 2020 Another communication is being sent this afternoon. They are hoping to bring back online this afternoon/evening.
eddyc Posted October 7, 2020 Posted October 7, 2020 I think it’s really poor tbh. It was offline first thing on Monday and they’ve provided no official communication until the email sent today. There should have been something sent on Monday to say that there has been an issue which is being investigated and it may be down for up to a week. I understand from my colleague in Finance that every day that WisePay has replied to an email this week they have said it will be back online this afternoon and this has been the case today, yesterday and Monday.
eddyc Posted October 7, 2020 Posted October 7, 2020 https://www.theregister.com/2020/10/07/wisepay_outage_was_cyber_attack/
enjay Posted October 8, 2020 Posted October 8, 2020 It's back! It is quite slow so possibly not running on their normal boxes. Forced password change at login, which is simultaneously reassuring and not!
JJonas Posted October 8, 2020 Posted October 8, 2020 I still have not had any emails about this. Another communication is being sent this afternoon. They are hoping to bring back online this afternoon/evening.
FN-GM Posted October 8, 2020 Posted October 8, 2020 Im not shocked. I sent them a message a few years ago about a security issue and they dismissed it.
enjay Posted October 8, 2020 Posted October 8, 2020 I still have not had any emails about this. We still haven't received the one telling us about the outage, but we have had the following about the resolution. We are writing in follow up to our previous notification about a data security incident that has occurred on your payment processing platform, WisePay. We believe the cyberattack was a URL manipulation in which the SagePay gateway page was spoofed, potentially allowing a cyber-criminal to access some individuals’ payment details. Many of the attempted transactions were refused as a result. We believe that the following data elements were unlawfully accessed: • Name of the cardholder; • Payment card number; • Card expiry date and CVC number. We can now confirm that individuals attempted to make payments to your School/College during the time period in question. Please get in touch with us at your earliest convenience so we can securely share this information with you. We have drafted a notification and some next-steps information for you to send to the affected parties, as well as an informational letter to send to those users who were not impacted. Our investigation, led by a cybersecurity forensics expert, remains ongoing, and we anticipate sharing more information about the incident with you directly. We have filed a report with the ICO and also notified Action Fraud and the National Cyber Crimes Agency. WisePay has implemented additional security measures designed to prevent a recurrence of such an event. Given that there are several investigations into this incident, including potentially by law enforcement, we request that you keep it confidential to the School and the relevant parents/carers. Please let me know if you have any other questions at this stage. We deeply appreciate your patience as we work through this matter. 1
JJonas Posted October 8, 2020 Posted October 8, 2020 Not seen that. Just phoned them about the lack of communication from them. I hope to hear something shortly.
witch Posted October 8, 2020 Posted October 8, 2020 My school heard nothing other than a phone call from the local senior school who HAD got the message Very poor communication
JJonas Posted October 8, 2020 Posted October 8, 2020 Still not had any response to my earlier phone call. However I do know one of my friends who tried to make a payment between the 2nd and the 5th has had money fraudulently removed from their account. So the hackers are using the information that was stolen. If you have made a payment between these dates you should contact your bank and get them to put a stop on purchases made while the card holder is not present. As well as getting them to send you a new card. By doing this you will still be able to use you card in shops but online transactions will be denied.
enjay Posted October 8, 2020 Posted October 8, 2020 WisePay have just told us they can't tell us who was affected because they are still working on a way to send the list of names securely.
paulkerton Posted October 8, 2020 Posted October 8, 2020 WisePay have just told us they can't tell us who was affected because they are still working on a way to send the list of names securely. Isn't that their job? To communicate directly with those affected?
eddyc Posted October 8, 2020 Posted October 8, 2020 I completely agree with you on this. Why should have I have to deal with our irate parents because of their own failing? They should make contact with those affected and provide whatever support is needed. Isn't that their job? To communicate directly with those affected?
DrBeaker Posted October 8, 2020 Posted October 8, 2020 I completely agree with you on this. Why should have I have to deal with our irate parents because of their own failing? They should make contact with those affected and provide whatever support is needed.I'd be mighty tempted to put an external forward on the relevent school phones to their customer support phone number. 1
enjay Posted October 8, 2020 Posted October 8, 2020 153 parents and staff potentially affected. We're going to get a lot of phone calls tomorrow!
Linfit Posted October 9, 2020 Posted October 9, 2020 Had to send 103 letters out today to parents they say are affected by this. Very unhappy that they have left the schools to communicate with parents and feel they should be contacting the parents direct. It also appears that they have not told some schools at all yet - another school in our MAT uses them and has had no communication with them at all.
eddyc Posted October 9, 2020 Posted October 9, 2020 I have emailed them (yesterday at 09:58) and received an out of office but no reply yet to confirm who in our school has been affected. Thank you for your email and for your patience. We are systematically working with schools and parents to achieve desired outcomes. We will be with you shortly. The whole thing is ridiculous. I understand our finance team are getting around 30 emails an hour for password resets from parents at the moment as WisePay seems to show "Not Given" as the email for a high percentage of our parents despite their email always being on their child's SIMS record. Had to send 103 letters out today to parents they say are affected by this. Very unhappy that they have left the schools to communicate with parents and feel they should be contacting the parents direct. It also appears that they have not told some schools at all yet - another school in our MAT uses them and has had no communication with them at all.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now