Notification

Publish date 22 August 2023

Dear Clients,

Pursuant to Article 34, §1 of Regulation (EU) 2016/679, we hereby inform you of a personal data security breach involving data processed by I&G Insurance Brokers EOOD.


1. Description of the Breach

I&G Insurance Brokers EOOD is an insurance broker registered in the public register of the Financial Supervision Commission. For the purpose of managing its operations, the company processes personal data related to the conclusion of insurance contracts. The company was the target of a malicious cyberattack, which likely affected the security of some personal data processed in the customer information system and resulted in unauthorized access to information containing personal data as defined by the GDPR.

According to the data processor, the breach involved a confidentiality breach due to unauthorized access to the company’s internal employee information system, which stores client details and insurance product information. The incident likely involved the compromise of login credentials (username and password) of one or more employees with limited access rights. The breach was discovered on August 19, 2023.


2. Categories and Approximate Number of Affected Data Subjects and Data Records

2.1. The breach affected the following category of data subjects: clients.

2.2. The compromised personal data records may include: full name, personal identification number (EGN), address, and phone number.

2.3. As of the time of this notification, the exact number of affected individuals and data records is not yet known.


3. Contact Person

I. Pavlova – Data Protection Officer
Phone: +359 2 813 88 13
Email: dpo@iandgbrokers.com


4. Description of the Possible Consequences of the Personal Data Breach

The potential consequences of the breach are still being assessed. They may include risks to the rights and freedoms of data subjects, which could result in material or non-material damage (e.g., breach of confidentiality, public disclosure of personal data, or access by malicious third parties).


5. Description of Measures Taken to Address the Breach, Including Measures to Mitigate Potential Negative Consequences

The following technical and organizational measures have been taken:

The incident was reported to the General Directorate for Combating Organized Crime, which will carry out an investigation.
An internal investigation has been initiated by the company.
The Personal Data Protection Commission has been notified of the breach.
Passwords for all company employees in the web application have been changed.
Additional technical measures have been implemented to enhance the security of personal data processed by I&G employees.
Based on our preliminary assessment, the risk level to the rights and freedoms of the affected individuals is considered limited. The assessment was conducted based on the nature, scope, context, and purposes of the processing, as well as other factors, in line with the Guidelines on Data Protection Impact Assessment (DPIA) and the determination of whether the processing is “likely to result in a high risk” under Regulation 2016/679.

We publish this notification for your information and remain ready to promptly update you on any developments related to the suspected breach.