The personal data of more than 148,000 customers and employees at two hearing and speech centres in Hong Kong has been leaked in a ransomware attack, the city’s privacy watchdog has said.
Widex Hong Kong Hearing and Speech Centre and its subsidiary, Starry Hearing and Speech Centre, announced in August that it had suffered a ransomware attack on July 5 that had encrypted their internal system data and impacted their applications.
While the centres did not disclose the number of people affected, the Office of the Privacy Commissioner for Personal Data estimated on Monday that about 148,000 customers and between 30 and 50 current and former employees had been affected.
The watchdog said the figures were based on preliminary information provided by the affected centres, with the final tally still under investigation. It added that it was notified of the incident on July 30.
The breach is suspected to have potentially exposed customer information such as their names, dates of birth, addresses, phone numbers, audiologists and hearing device records.
The leaked data of current and former Widex employees comprised their names, salary details, retirement benefits, bonuses and bank account numbers.
Widex is a Denmark-based company that was founded in 1956 and specialises in hearing aids and related services. It offers a range of hearing devices designed for people suffering from hearing loss.
It also provides hearing tests, speech therapy and tinnitus care services.
Its Hong Kong branch was established in 1986 and is one of the first private institutions to offer hearing and speech therapy services in the city.
The local branch operates six centres that provide hearing assessments, hearing aid prescriptions and speech and swallowing therapies, among other services.
WS Audiology, Widex’s parent company, shared more details on the breach on September 10, saying the incident involved the local retail IT system for Bloomhearing stores in Australia and New Zealand on July 5.
The incident had also affected some data-related operations in Hong Kong and Singapore, it added.
WS Audiology said the perpetrators had gained temporary access to the personal data of its patients and employees.
While the data could have been copied, it was not lost due to the company’s backup systems, it added.
The two affected centres in Hong Kong said they had taken immediate action to contain the incident and secure their own IT systems, in addition to notifying the watchdog and actively cooperating with its investigations.
“We are actively liaising with the authority and will continue to do so until this matter is resolved,” they said.
Widex has advised those affected by the leak to update their passwords, activate multi-factor authentication systems where possible and maintain good online security practices, such as avoiding opening messages or clicking on links from unknown senders.
“We know this is a concerning development but rest assured your privacy and security are of utmost importance to us. We sincerely apologise for any distress this incident may have caused,” it said.
The company advised its clients to monitor the website for further updates if they believed they could have been affected.
It added that it would continue to investigate the extent of the breach and promised to provide updates when more information became available.