Webbers Estate Agents has warned clients that their personal information may have been compromised following a security incident.

The incident involved a third-party service provider rather than Webbers’ own systems, according to the agency.

The South West firm contacted customers this week after becoming aware of the incident.

Webbers said the affected information could include names, addresses, telephone numbers and email addresses.

The agency operates across Devon, North Cornwall and Somerset. Its offices include branches trading under the Webbers and Fine & Country brands.

Webbers stressed that its own security had not been breached. Instead, it said third-party organisations working with the business had suffered the data breach.

The incident highlights the cyber-security risks facing agents that use external suppliers with access to client information.

ICO informed

In its initial communication, Webbers said: “We are obliged to inform you that we have been made aware, at approximately 4pm today of a security breach that may have affected your personal data.”

It said the information included names, addresses, telephone numbers and email addresses.

The agency added: “I would like to stress that our own security has not been breached.”

Webbers said the data was compromised through third-party organisations that work with the agency.

It is now working with those organisations to establish the extent of the breach.

‘Subset of our clients’ affected

Webbers has confirmed that it notified the Information Commissioner’s Office (ICO).

A spokesperson said: “We are investigating an IT incident which affected a third-party service provider.

“Our present understanding is this involved basic contact details for a subset of our clients.

“We are liaising closely with our clients and the relevant authorities on a precautionary basis.”

Webbers has not disclosed how many clients may have been affected. It has also not identified the third-party provider involved.

Based on the information currently available, the agency has not reported any compromise of financial information or passwords.