Naivas Supermarket contravened timelines on reporting data breach-Kassait

Naivas Supermarket contravened timelines on reporting data breach-Kassait
Data Commissioner Immaculate Kassait/PBU

NAIROBI, Kenya, Sep 20 – The Office of Data Protection has revealed that Naivas Supermarket retail chain breached the law by failing to report Customer Data hacking within the stipulated 72-hour timeline.

Appearing before the Senate ICT Committee, Data Protection Commissioner Immaculate Kassait told Senators that Naivas failed to initiate adequate measures to safeguard the data stored in the servers to the extent that they were unable to determine the exfiltrated personal data.

Kassait stated that the preliminary forensic investigation report showed that the breach of the data resulted from a ransomware attack by Alpha Spider.

She stated that immediate measures have been taken including isolation of affected systems and installation of endpoint protection.

The Data Commissioner disclosed that a post-breach audit and inspection has commenced to ensure all precautionary and culpability actions are undertaken based on the findings of the report.

 “While immediate measures have been implemented, a further detailed inspection and audit is being undertaken by the Office to confirm the current safety of customer, supplier and employee data held by Naivas, the office does not have the final forensic report submitted, it affirms that it is dedicated to ensuring that all necessary precautions are in place to secure the data,” said Kassait.

Details have shown that the Naivas Supermarket data breach resulted in the breach of personal data which included names, phone numbers, email addresses, and loyalty points, were exposed.

“There is no information provided that suggest that customer purchasing patterns were part of the compromised data or that the information was exposed to the public, my office has initiated an audit and inspection of the organization to ascertain the extent of the organization’s recovery, impact of the breach and ensure the mitigation of any adverse effects on the data subjects,” Kassait stated.

Kassait said they have been consistently monitoring the supermarket’s initiatives to ensure they are aligned with the relevant data protection laws on the protection of individual rights.

 “The Office of the Data Protection Commissioner has reviewed the measures taken by Naivas to respond to the breach, actions include isolating affected systems, engaging third-party forensic experts and implementing endpoint protection, Naivas has expressed intentions to put additional measures in place post-breach,” said Kassait.

The Office of the Data Commissioner directed Naivas to disseminate information and answer questions by telling stakeholders about the incident and measures taken to avert further losses.

 Following the data breach, the Office of the Data Commissioner reported that Naivas has put in place necessary policies, access controls, logging and monitoring procedures, and data backups on both online and offline servers in addition to other privacy-enhancing safeguards, including encryption of data both in transit and at rest.

In a letter to the Data Commissioner, Naivas Supermarket Legal Manager Jean Wambui said that a virus attack compromised the retail chain outlet IT system on March 2.

Wambui said the nature of the virus was denial of service and encryption of files pointing out that they were not aware if any personal data had been accessed and whether personal data had been extracted.

 “We have cleaned up the environment and reconciled databases, we have reset passwords for all employees, installed updates antivirus software, formatted and restored Naivas servers and databases, migrated users and computer devices to a new active directory,” said Wambui.