Notice of Data Security Incident
Cambridge recently notified affected individuals regarding a recent data security incident that involved some of their personal information.
What Happened
We were recently informed that an unauthorised third party gained access to Cambridge’s customer relationship management (CRM) data as a result of a security incident involving Klue, a third-party market intelligence platform that Cambridge integrates with our CRM platform. The unauthorised third party accessed CRM data belonging to multiple Klue customers, including ours, between 11 and 12 June 2026. Upon becoming aware of the incident, we immediately engaged cybersecurity experts to investigate, assess any potential impact and notify relevant authorities.
What Information Was Involved
Information may have included names, email addresses, residential addresses, dates of birth, financial information, identification information (e.g., passport number, drivers licence number), Tax ID, citizenship information, and/or politically exposed person status.
What We Are Doing
-
We launched an investigation with the support of third-party experts to take steps to mitigate and remediate the incident and to help prevent further unauthorised activities.
-
We have further enhanced our security and monitoring practices and implemented additional safeguards across our own systems aimed at minimising the risk that a similar incident occurs in the future.
What Happens Next
While our broader investigation is still ongoing, we have concluded our investigation into the specific data affected for Australian individuals and we have provided formal notice to these impacted individuals.
What You Can Do
Included below are some recommended steps that you can take to help protect yourself and your identity if your personal information is affected by a data breach:
-
Regularly change passwords and ensure that industry-standard password complexity recommendations are followed.
-
Enable multi-factor authentication on accounts, where available.
-
Regularly monitor bank and credit card statements and report any unusual activity to your bank as soon as possible. As necessary, contact the police if there has been suspicious activity on your account. Some banks may also enable you to set up alerts for withdrawals or charges above a certain limit to help identify potential fraudulent transactions early.
-
Consider requesting a credit lock or block through your national credit reference agency.
-
Be alert to phishing attempts and do not click on links or open attachments in unsolicited emails or messages. As necessary, verify the sender before responding.
-
Update software and devices regularly to ensure the latest security patches and antivirus updates are applied to reduce vulnerabilities.
-
Use secure networks and avoid accessing sensitive accounts over public Wi-Fi unless you are using a trusted VPN network.
