Main Navigation
  1. What we do

    About the PMI Empowering change through education

    We are the UK's leading professional body dedicated to supporting and developing experts who manage UK pension schemes. Our members represent and lead in every aspect of pension management.
  2. Membership

  3. Learning & development

    Learning & development Achieve your career goals with the PMI

    The PMI provides qualifications, training, and resources designed to support your career goals, no matter where you are in your professional journey.
  4. Training

    Training Training that turns knowledge into action

    Practical, expert‑led training designed to build real world skills, boost confidence, and deliver measurable results, whether you’re upskilling individuals or empowering teams.
  5. Events

    Events Connecting the pensions industry

    Connect and learn from industry experts through our conferences, workshops, exhibitions, and local events
  6. Resources

Tags
News

01 September 2020

Security incident

To all our members and those who were affected by the security incident on 1 September 2020.

Last week one of our staff had their Outlook email account targeted and hacked.

The attack was sophisticated with the perpetrator using a VPN through a Manchester data centre to gain access to the individual's email inbox. Once inside, they were able to see a number of member and other stakeholder email addresses. It is not known at this stage where the attack originated from in the world, but our IT experts are working in close collaboration with Microsoft and others to investigate.

As soon as we became aware of the incident, we initiated our internal protocols in respect of data breach management. We also shut down the staff member's email account. We engaged the support of the Information Commissioner's Office, IT specialists and our legal advisers.

Our IT company immediately began a full and thorough investigation. They have assured us that our iMIS member database has not been compromised, nor any financial systems, nor have any of our other IT infrastructure assets due to our own VPN and other protective measures being in place. As we are working remotely, they have also checked all staff laptops and have confirmed them to be clean with all security measures up to date.

Our investigations indicate that just under 1,700 people had their details compromised. We have contacted all those affected.

I would likely to publicly apologise for any inconvenience that may have been caused by this attack and offer our reassurance that we are taking all appropriate steps to ensure that this never happens again.

We will inform individuals should the results of our investigation suggest further impact on the processing of their personal data and urge anyone that received the phishing email to delete it immediately. As an additional precaution, and in line with our incident response protocol, we request all users of MYPMI update their passwords as soon as possible.

 

If you have any queries, please contact us here.

opens in new window