TalkTalk investigating data breach after hacker claims theft of customer data

Date:

Share post:


U.K. telecoms giant TalkTalk has confirmed that it is investigating a data breach after a hacker claimed to have stolen the personal information of millions of customers.

In a post on a popular cybercrime forum seen by TechCrunch, an individual using the alias “b0nd” claimed to have stolen the personal data of more than 18.8 million current and former TalkTalk subscribers. This data, which the threat actor is offering for sale, supposedly includes customer names, email addresses, IP addresses, phone numbers and subscriber PINs. 

In a statement to TechCrunch, TalkTalk spokesperson Liz Holloway confirmed the company is investigating the data breach, but said the 18.8 million figure claimed by the hacker is “wholly inaccurate and very significantly overstated.”

TechCrunch understands that TalkTalk currently has approximately 2.4 million customers.

“As part of our regular security monitoring, given our ongoing focus on protecting customers’ personal data, we were made aware of unexpected access to, and misuse of, one of our third-party suppliers’ systems,” Holloway told TechCrunch. “Our Security Incident Response team are continuing to work with the supplier regarding this matter and protective containment steps were taken immediately.”

Holloway declined to name the third-party supplier, but screenshots shared by b0nd suggest the data was stolen from CSG’s Ascendon platform, which TalkTalk uses for subscription management.

CSG did not immediately respond to TechCrunch’s questions. 

TechCrunch understands that the personal details of a small subset of TalkTalk customers are stored in Ascendon. Holloway confirmed to TechCrunch that “no billing or financial information was stored on this system.”

TalkTalk was previously fined £400,000 after a 2015 data breach in which hackers stole the personal data of 157,000 customers, including some financial information. The U.K.’s Information Commissioner said at the time that TalkTalk had failed to implement “the most basic cyber security measures,” enabling hackers to “penetrate its systems with ease.”



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

SoftBank in talks to invest as much as $25B in OpenAI, report says

SoftBank is in talks to invest up to $25 billion in OpenAI as part of a broader...

Meta says end of fact-checking hasn’t impacted ad spend

Meta says its controversial decision to put an end to its fact-checking program hasn’t impacted advertiser spend....

Zuck shrugs off DeepSeek, vows to spend hundreds of billions on AI

U.S. markets panicked on Monday over speculation that DeepSeek’s AI models would crush demand for GPUs, with...

LinkedIn passes $2B in premium revenue in 12 months, with overall revenue up 9% on the year

LinkedIn, the social platform where people look for and talk about work, may be less visible in...

Elon Musk claims Tesla will launch a self-driving service in Austin in June

Tesla CEO Elon Musk said Wednesday his company will launch a paid ride-hailing robotaxi service in Austin,...

Threads adds another 20M monthly users since December, reaching 320M

Threads, Meta’s microblogging service, is growing at a fast pace as users gravitate to the app over...

Hackers are hijacking WordPress sites to push Windows and Mac malware

Hackers are exploiting outdated versions of WordPress and plugins to alter thousands of websites in an attempt...

Microsoft brings a DeepSeek model to its cloud

Microsoft’s close partner and collaborator, OpenAI, might be suggesting that DeepSeek stole its IP and violated its...