TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

TalkTalk cyber-attack: Website hit by 'significant' breach

41 pointsby sjclemmyover 9 years ago

7 comments

scootover 9 years ago
First, the level of technical incompetence is staggering:<p>* Two significant breaches in 7 months * Bank&#x2F;CC and personal details stored unencrypted * Pssswords stored in cleartext * &quot;We have taken all necessary measures to secure the website.&quot; That&#x27;s what they said last time.<p>Second, the response is laughable:<p>* Two days since the breach was discovered, and customers still haven&#x27;t been notified. * No mention of the breach on the talktalk.co.uk home page. * The site in question [1] says it is offline due to an attack, but doesn&#x27;t like to the relevant help page [2]<p>[1] <a href="https:&#x2F;&#x2F;myaccount.talktalk.co.uk&#x2F;" rel="nofollow">https:&#x2F;&#x2F;myaccount.talktalk.co.uk&#x2F;</a> [2] <a href="http:&#x2F;&#x2F;help2.talktalk.co.uk&#x2F;oct22incident" rel="nofollow">http:&#x2F;&#x2F;help2.talktalk.co.uk&#x2F;oct22incident</a>
评论 #10437768 未加载
评论 #10437908 未加载
评论 #10438095 未加载
评论 #10438298 未加载
ctzover 9 years ago
Paul Moore&#x27;s findings from one year ago: <a href="https:&#x2F;&#x2F;paul.reviews&#x2F;value-security-avoid-talktalk&#x2F;" rel="nofollow">https:&#x2F;&#x2F;paul.reviews&#x2F;value-security-avoid-talktalk&#x2F;</a>
dtfover 9 years ago
Someone on the radio just said it was an SQL injection. Can it get any more comical?<p>Meanwhile TalkTalk &amp; Met Police PR machines are in full flow talking up exotic claims of cyberjihadiism to deflect responsibility.
oneeyedpigeonover 9 years ago
They have now, apparently, received a ransom demand: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=10438175" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=10438175</a>
评论 #10438413 未加载
stzup7over 9 years ago
&quot;TalkTalk&#x27;s speedy decision to warn all of its customers that their vital data is at risk suggests that this one is very serious indeed.&quot;<p>Not all its customers obviously. I left Talktalk a month ago as a customer but I could still login to my account online to download and settle my final bills. I&#x27;m pretty sure they still store my bank account and credit card info on their end and they didn&#x27;t warn me about the attack...
评论 #10437550 未加载
baucover 9 years ago
Do CEOs&#x2F;directors of companies get hit but these data breaches, do we need to start insisting their personal&#x2F;banking data is stored the same as customers so they get impacted? Too many companies just don&#x27;t take security seriously enough.
评论 #10437803 未加载
tonylemesmerover 9 years ago
I was briefly a customer about 4 years ago - I wonder if my details are in the cache.