Following an earlier statement (here) Malindo Air has given more details of how its data breach came about.

Financial crime risk management - be it related to money laundering, terrorist financing, fraud or embezzlement purposes, to say nothing of anti-bribery requirements - is expensive. For small businesses, it's cost prohibitive. Compliance is even worse. Is it feasible, permissible, even advisable to share the burden with others?

Customer Response Centres (CRCs) are the point of contact for every disgruntled customer. They are the public face of the enterprise. They are also often far (in both management and geography) removed from the company that the customer thinks he is dealing with. Performance is measured and the amount paid to the CRC operator depends on achieving defined Key Performance Indicators, or KPI. However, some CRCs are producing false KPIs which, because they are what payment depends upon, are in fact false accounting and fraud. Here's how it's happening.

