Important information about your account security.
Dear Chu,
Weâre writing to you to let you know about a data security incident that has impacted people whoâve registered, or attempted to register, for a Pepperstone demo or live trading account.
Our investigations show that the personal information (or personal data) about you that may have been impacted is limited to your:
- Name
- Contact details (such as email, phone number and physical address)
- Date of birth
We can confirm that any trading accounts, passwords and bank account information that you have with us are safe. They have not been compromised.
Weâre extremely concerned that this has happened. Keeping your Pepperstone account safe is our priority. Please be assured that weâve identified the cause of the incident, contained it, and put a number of measures in place to stop it from happening again.
What happened?
Like most businesses, Pepperstone uses a variety of third party service providers to undertake various functions. On 22 July (AEST) we discovered and contained a malware attack. One of our service providers was attacked by criminals who used malware to compromise a computer used by the service provider in order to steal their user credentials. The cyber criminals then used those credentials to gain access to our internal client relationship management system. Before we stopped the attack, they were able to take a limited amount of personal information belonging to some of our account holders. The criminals accessed a subset of our account holder data via the client relationship management system. Importantly, the criminals werenât able to access our trading environment or our financial systems, which are segregated from our client relationship management system. This means that the criminals didnât gain access to any trading accounts, banking details, passwords or ID documents that we hold for you. Our clients can continue to have confidence in using our trading systems safely and securely. For more details about the incident, how weâve stopped it and prevented it from recurring, please visit our dedicated webpage.
What has Pepperstone done to address this?
We first became aware of this issue on 21 July and immediately launched an investigation with the assistance of an external forensic specialist. Weâre also in communication with the national cyber crime agencies and data privacy commissioners in our regulated jurisdictions. Weâve only recently become aware that your details were impacted as a result of that investigation.
What do I do now?
We encourage you to take the following steps:
- Configure your Pepperstone account and other online accounts, such as email, to require two-factor authentication (e.g. password plus SMS code)
- Although we have no reason to suspect that your password has been compromised we strongly recommend that you change your Pepperstone password as a precaution. We also recommend that you choose a password thatâs unique, not one that you use for any of your other online accounts
- If you believe that your personal information has been used by a third party without your authorisation, report it to your local cybercrime agency
- Contact your bank immediately if youâve sent money to a scammer or if you think youâve provided confidential banking information to a scammer
- Donât allow any access by remote desktop viewers by any company, even if they claim to be Pepperstone
- Donât respond to/click on any suspicious communications from people or organisations that you donât know
- Close any online accounts that you no longer use.
We understand that people will be concerned about this. We encourage you to contact us immediately if you have any suspicions or concerns about any communication you receive, on 1300 033 375 or at support@pepperstone.com.
Finally, we want to reassure you that Pepperstone absolutely remains open for business, fully regulated and here to support your trading needs. If you want to discuss this matter further please donât hesitate to get in touch.
Kind regards,
The Pepperstone team