Sage have no idea who's data was shared to unauthorised parties
We use the Sage cloud based accounting platform. It's a very popular package with small to medium sized businesses and following our own risk assessment we implemented it about 3 years ago. It work(ed) well etc.
However, following the report here - and Sage's response to El Reg - I thought we would simply ask them one question. "Was our data shared with any other Sage user during or due to this incident?".
It's a simple enough question and five days later they have written to us with the following response:
"Sage Copilot > CASE-<redacted>
Dear <redacted>,
Thank you for contacting us. We are aware of your request for confirmation as to whether your data has been shared to a third party based on the Sage Accounting inc Sage Copilot issue we had last week. We will look into this and will come back to you with more information once we have investigated.
Kind regards
<redacted name> She/Her/Hers
Customer Relations Specialist
Office 0191 4795989 (UK)"
There's the real problem - they have no idea - and we are not even on the AI/CoPilot trial.
This suggests that even if you are not on the trial, you data has been leaked or used to train the system and been made available to others.
This isn't going to end well for Sage.