In an email sent to customers, EasyEquities said the third-party provider had experienced a cybersecurity incident that may have affected customer information.
The company said an immediate forensic investigation has been launched by the service provider to establish the nature and extent of the incident, including what information may have been affected.
EasyEquities says its systems were not compromised
EasyEquities says it has also conducted its own internal security checks following notification of the incident.
According to the company, the investigation found no evidence that any EasyEquities or Purple Group Limited systems were compromised. EasyEquities also stated that there has been no impact on customers' account security or their ability to invest.
However, the investigation into the third-party provider has not yet been completed. EasyEquities says it will communicate further with customers if necessary once it receives the final investigative report.
Customers urged to be alert
EasyEquities is warning customers to be particularly cautious about unsolicited emails, phone calls or messages claiming to be from EasyEquities or another party involved in the incident.
Customers have been advised not to click suspicious links or provide personal or account information to unknown parties. The company also asks customers who are contacted by someone claiming to have their information because of the incident not to engage with them and to notify EasyEquities immediately.
The warning highlights an important reality of modern cybersecurity: an organisation's security can also depend on the security of the third-party companies and services it relies on.
Could your organisation detect vulnerabilities before attackers do?
The EasyEquities incident is another reminder that cybersecurity should not only be considered after something goes wrong.
Businesses should regularly assess their websites, servers, applications and internet-facing infrastructure for vulnerabilities and potential security weaknesses.
One option businesses can consider is Cyber Security Bug, an online vulnerability assessment and penetration-testing platform designed to help organisations identify potential security weaknesses before criminals can exploit them.
Cyber Security Bug can be used to assess systems for vulnerabilities and security issues, helping businesses gain greater visibility into weaknesses that may otherwise go unnoticed.
Don't wait for an attack to discover a vulnerability
A cyberattack can happen without warning, and many businesses may not know that a vulnerability exists until someone exploits it.
Regular security assessments can give organisations an opportunity to identify weaknesses, investigate them and take corrective action before they become a bigger problem.
The lesson for businesses is simple: don't wait for a cyberattack to tell you that your systems have vulnerabilities. Test your security before attackers test it for you.
Scan. Identify. Fix. Protect.
Visit Cyber Security Bug to learn more about vulnerability assessments and cybersecurity testing.