SLB apologises for email distribution error
KINGSTON, Jamaica — The Students’ Loan Bureau (SLB) is advising customers of an inadvertent email distribution error that occurred on Tuesday, September 8, during the dissemination of its SLB Insights newsletter.
According to the SLB in a statement on Wednesday, the newsletter was being distributed to customers as part of its ongoing communication regarding loan repayment obligations. It said during the distribution process, a customer email distribution list was inadvertently attached to one batch of the mailing in place of the intended newsletter.
“This was an error on the bureau’s part in the execution of that distribution. The affected file contained a list of customer email addresses only. It did not contain separate fields with customer names, loan account numbers, loan balances, Taxpayer Registration Numbers (TRNs), dates of birth, residential addresses, telephone numbers, banking information, passwords or other account credentials,” said the SLB.
SLB said the error affected only one batch of the distribution.
“The file was not published on SLB’s website, social media channels or other public platforms. The bureau is continuing to verify the final scope of the affected distribution and whether there is any evidence of further dissemination. The incident did not alter any customer’s loan account, balance, repayment obligation or account status. There is currently no indication that the incident resulted from unauthorised access to SLB’s systems or from malicious activity. The matter was identified and escalated for investigation on the same day it occurred,” the bureau added.
The bureau said it has initiated a review of the incident and of the controls governing bulk customer communications, including confirmation of the scope of the affected distribution and the implementation of additional safeguards to reduce the possibility of a recurrence.
“Bulk email distributions using the affected process have been suspended while additional safeguards are implemented. The matter has been reported to the Office of the Information Commissioner in accordance with applicable requirements. Customers identified as affected are being contacted directly by the bureau,” the SLB said.
It noted that as a precaution, customers should remain vigilant for suspicious or unsolicited communications that may appear to originate from the bureau.
“SLB takes seriously the responsibility entrusted to us to safeguard customer information,” said Nickeisha Walsh, executive director. “Customers should not disclose passwords or one- time passcodes in response to unsolicited emails and should verify any suspicious communication directly with SLB through its official channels.”
The executive director added: “This was an error on the bureau’s part, and we apologise to the customers affected. Our customers are entitled to expect that information entrusted to SLB will be handled with appropriate care. We are addressing the immediate incident and strengthening the processes and system controls governing bulk customer communications to reduce the risk of a recurrence.”
The SLB said it remains committed to communicating transparently with affected customers while ensuring that information released about the incident is accurate and based on verified findings.