SHINDO4

Gibraltar Life

Customers7,278people

EXPOSEDFull name / Contract detailsSoftware defect · Contained

Open in the live monitor ▶
Disclosed
Feb 4, 2025
Detected
Nov 13, 2024
Detection to disclosure
83 days
Leak
Exposed, access unknown
Type
Software defect
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityNames of policyholders and insured persons
Transactions & activityPolicy number
Financial & paymentPremiums, surrender values, etc.

How many

  • Customers 7,278 people
  • Statements 7,606 records

Who is affected

  • Policyholders and insured persons of four products, including variable-rate whole life insurance

Cause

Because of a system design error, when viewing statements such as the policy summary, a customer could under certain conditions see one other customer's policy data

Timeline

  1. Detected
  2. Date of the Security NEXT report (earliest disclosure seen)

Response

  • Change process
  • Notified individuals

Fixed the faulty system and emailed affected customers

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Never sit on a known defect. Test every change before production
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources