Forum menu
Talk Talk Hacked Ag...
 

[Closed] Talk Talk Hacked Again......

Posts: 17846
Full Member
Topic starter
 
[#7410066]

Heard on the radio that Talk Talk have been hacked again.

I know this can perhaps happen to any large company these days, but that's at least twice now and I think it's time to look for an alternative - the broadband service is not very good anyway and we frequently get phone calls pushing us to sign up to their TV box which we don't want, so no good reasons to stay with them.

We've already ended up having daily 'Talk Talk customer service' calls from people doing the 'Microsoft style fraud' as a result of the last hack.

What provider are people using for phone & broadband. Any you can recommend? Any you don't recommend!?!
PlusNet always seem to pop up as a good provider to go for.
How about BT? Always seem a bit more expensive, but perhaps you get what you pay for?


 
Posted : 23/10/2015 8:17 am
 hels
Posts: 971
Free Member
 

I would be interested to hear what happened with this one - how did they get bank account numbers from a website hack ? Somebody isn't doing their security properly.

They were saying on radio 4 this morning the stolen data has already turned up on t'internet.


 
Posted : 23/10/2015 8:20 am
Posts: 0
Free Member
 

Been with PlusNet for a llloooonnnnngggggggg time, can't fault them. I've never had any trouble at all, and any time I've heard of someone that has it's actually been a BT element that's let them down


 
Posted : 23/10/2015 8:21 am
 hels
Posts: 971
Free Member
 

I have used BT for years - they only stuff up they have made was sending me the alert that my broadband was WAY over usage to a BT email account I didn't even know I had, let alone use.

I managed to get the charges refunded with no arguments, as I definitely didn't use the astronomical amount they were trying to charge me for.


 
Posted : 23/10/2015 8:22 am
Posts: 14104
Full Member
 

I'm with TalkTalk too. They only have my bank details (not credit/debit card) so I'm not sure how they could get money out. The information they have is only what would be on a cheque.

Am I wrong?


 
Posted : 23/10/2015 8:29 am
Posts: 738
Full Member
 

That's what I was wondering too.


 
Posted : 23/10/2015 8:31 am
Posts: 0
Free Member
 

Little risk in them having your bank details.
Much more risk in them having your password, if you re-use the same password across many sites as some folk tend to do.


 
Posted : 23/10/2015 8:40 am
 Drac
Posts: 50598
 

It said there was a chance that some of the following customer data, not all of which was encrypted, had been accessed:
Names and addresses
Dates of birth
Email addresses
Telephone numbers
TalkTalk account information
Credit card and bank details

Yup exactly what's on a cheque.


 
Posted : 23/10/2015 8:40 am
 hels
Posts: 971
Free Member
 

Yes, I always put my address and date of birth on a cheque, usually with my mother's maiden name, you know, in case somebody wants to send me a birthday card.


 
Posted : 23/10/2015 8:42 am
Posts: 0
Free Member
 

I've been with BT for a few years after moving from sky (I had a really bad service from sky, it was really slow at peak times and very intermittent connection) moved to infinity and obviously it's faster but it's a constant connection and BT have been great to deal with.

My sister is also with BT and I moved in about three months ago, no one told me that it was only a 40gb a month plan so when I ate through 500gb in the first month they recieved a massive bill! My BIL rang up to question it and they refunded without question and upped his plan for free.

All in all I would recommend BT.


 
Posted : 23/10/2015 8:47 am
Posts: 17846
Full Member
Topic starter
 

the-muffin-man - Member

I'm with TalkTalk too. They only have my bank details (not credit/debit card) so I'm not sure how they could get money out. The information they have is only what would be on a cheque.

Am I wrong?

What they are saying on the website is that the hackers can't access your bank account through this hack (obviously), but the details can be used for identity theft or online fraud - so check your accounts regularly over the next few months for suspicious activity & report anything you see.

The TalkTalk website does mention a year of credit monitoring for all affected customers, with details to follow.
I'm not sure entirely what that means, but it sounds mildly re-assuring from a credit rating point of view.

So, PlusNet & BT looking like likely contenders at the mo....


 
Posted : 23/10/2015 8:50 am
Posts: 3453
Full Member
 

Cannot see the mention of credit rating...where is that? Heard CEO on radio 5 mention it...off to plusnet I think,


 
Posted : 23/10/2015 8:58 am
Posts: 12
Free Member
 

Guys - this is really shit.

And I'll explain why: I work for TalkTalk. And I'm a customer.

This is the first data loss suffered directly by us: the first two were as a result of thefts from two partner organisaitons. Legal activity is ongoing with both of them.

This was a direct criminal attack to steal the personal data of 4m customers. We are often under DDOS attack - all large businesses are - and this initially looked like that. But it quickly became clear that it was more than that, hence us taking our sales sites offline.

Because it's a criminal attack the police are already involved - it's not clear yet where the attack has come from, though a Russian terrorist group is currently claiming responsibility.

We have advice for our customers: if you are or think you're affected then go [url= https://myaccount.talktalk.co.uk/home/dashboard ]HERE[/url] and [url= http://help2.talktalk.co.uk/oct22incident ]HERE[/url] for more information.

If you try to call please note that there are huge queues into the contact centres, so please be patient.

We're also emailing every customer (this will take time to avoid overloading the systems further) and are also writing to those who may not pick up up their emails.

You can also find info via our online community teams on [url= https://twitter.com/TalkTalkCare?ref_src=twsrc^google|twcamp^serp|twgr^author ]Twitter[/url].

As an organisaiton we're really sorry this has happened and are working hard to find out the scale of the attack and the potential impact on our customers.

Like I say, it's really shit.


 
Posted : 23/10/2015 9:00 am
Posts: 12
Free Member
 

The TalkTalk website does mention a year of credit monitoring for all affected customers, with details to follow.
I'm not sure entirely what that means, but it sounds mildly re-assuring from a credit rating point of view.

It's so that all customers are able to keep a close eye on their credit file as a methiod of spotting fraudulent activity (e.g, to spot credit searches made against their name that they haven't instigated).

I'll be using it and I shall be speaking to my bank today to get some checks put on transactions.


 
Posted : 23/10/2015 9:03 am
Posts: 3453
Full Member
 

Ourman......thanks for the posts really helpful....still cannot see how to use it nor mention on the site.....am I missing something?


 
Posted : 23/10/2015 9:13 am
Posts: 17846
Full Member
Topic starter
 

oumaninthenorth - thanks for the explanation...

We've been a customer for quite a while now (the whole time we've been in our current house - almost 5 years and probably about 2 years before we moved).

While I can see that it must be massively frustrating for you & the rest of the TalkTalk staff (you e-mailed me a while back after I mentioned on here the 'customer service hack' phone calls I was getting) - as an outsider, it does seem to be that TalkTalk are more susceptible than other firms to successful cyber attacks?
It's irrelevant to the customer whether attacks occur to TalkTalk themselves or to 'partner organisations' if the end result appears to be the same.

It's good to see that there are plenty of measures being taken, and I appreciate you posting here & including the links that you have.


 
Posted : 23/10/2015 9:14 am
Posts: 17846
Full Member
Topic starter
 

vondally - Member

Ourman......thanks for the posts really helpful....still cannot see how to use it nor mention on the site.....am I missing something?

The talk talk page I looked at earlier said that details are to follow (on the credit monitoring), so I imagine you'll get an e-mail or a letter in due course to explain more. I suspect that is something that takes a while to organise for 4m people!!


 
Posted : 23/10/2015 9:15 am
Posts: 12
Free Member
 

It's irrelevant to the customer whether attacks occur to TalkTalk themselves or to 'partner organisations' if the end result appears to be the same.

Absolutely right. Ultimately it's the people affected - our customers - and they should not have to worry about how or where it's happened.

Ourman......thanks for the posts really helpful....still cannot see how to use it nor mention on the site.....am I missing something?

Once the email comms start filtering through there will be info there on how to utilise the service.

@ stumpy - yes, emailing 4m customers and not causing them any other service issues does take some time!


 
Posted : 23/10/2015 9:20 am
Posts: 3453
Full Member
 

Stumpy get that and yes understand however as an internet naysayer and doom just feels all my pigeons and fears may have come home to roost....... ๐Ÿ™

Plus (all credit to ourman) may experience with talk talk has been dire recently we have been with them nearly a decade, so was going to move but did not so more frustration.


 
Posted : 23/10/2015 9:23 am
Posts: 0
Free Member
 

So, last time it happened my banks changed my cards.

The credit monitoring has got to happen now. I'm tempted to just get it organised myself.

Are there sufficient grounds to leave talk talk based on this?


 
Posted : 23/10/2015 10:02 am
Posts: 293
Free Member
 

My mum left talk talk because they are with out doubt the worst company she has ever dealt with. Cut off her phone and the only number she could phone was the bank. This is an 84 yr old lady who is a bit doddery. Vile scumbag company.

Would talk talk of deleted her details?


 
Posted : 23/10/2015 10:10 am
Posts: 13594
Free Member
 

Don't worry the Government has your back on this and have a great master plan, which is to ban any company from using strong encryption when storing your data! You couldn't make this shit up if you tried....

http://techcrunch.com/2015/01/13/politics-meet-technology/


 
Posted : 23/10/2015 10:27 am
 hels
Posts: 971
Free Member
 

Footflaps - have you heard the latest advice re passwords ? Don't bother changing them, that's too hard, just pick a really AWESOME one that you will remember so you can fully engage with the new fantastic and in no way smug and self-justifying Digital world.


 
Posted : 23/10/2015 10:34 am
 beej
Posts: 4210
Full Member
 

My service was switched from TalkTalk to another provider on Wednesday. I'll still be at risk as my details were still on the system, as will anyone else who has left and their details kept.

Will the year's worth of credit monitoring be given to all people whose details have been taken, or just those who are still customers?

It's unlikely I'll get phishing phone calls though as my number was changed in the switch over.


 
Posted : 23/10/2015 10:36 am
Posts: 1365
Free Member
 

I suggest a free experian 12month subscription for their 4 million customers. ( or sign up to noddle)


 
Posted : 23/10/2015 10:41 am
Posts: 12
Free Member
 

I suggest a free experian 12month subscription for their 4 million customers.

That's effectively what will be provided to every customer.


 
Posted : 23/10/2015 10:56 am
Posts: 12
Free Member
 

I'll still be at risk as my details were still on the system, as will anyone else who has left and their details kept.

I'll raise this internally to make sure we're covering former customers who may have been affected.


 
Posted : 23/10/2015 10:57 am
Posts: 6985
Free Member
 

*tangent, avoid noddle if you dislike spam, no such thing as a free lunch.

ex customer, ex-tremely hacked off although i understand the requirments to hold data for set periods.

Names? and addresses?
Dates of birth?
Email addresses
Telephone numbers
TalkTalk account information
Credit card and bank details


 
Posted : 23/10/2015 11:31 am
Posts: 12
Free Member
 

I'll still be at risk as my details were still on the system, as will anyone else who has left and their details kept.

The intention is that, where it's still relevant, we will communicate with everyone potentially affected. That's why there are a series of channels of communication, including the heavy media and press efforts we did last night (there are a lot of people who haven't been to bed for the last couple of days on this...).


 
Posted : 23/10/2015 11:41 am
 beej
Posts: 4210
Full Member
 

Thanks for the updates OMITN. I've been through similar crisis situations at another telecom company (not a hack - massive database corruption) and it's not much fun trying to sort it out.


 
Posted : 23/10/2015 5:50 pm
Posts: 0
Free Member
 

Just listened to someone on R4 explaining that it was a SQL injection attack on the back of a DDOS. I'm far for even an amateur in this field but i thought SQL injection is one of the most basic forms of hacking. Shouldn't their server have been protected from this?


 
Posted : 23/10/2015 5:58 pm
Posts: 4331
Full Member
 

I was with talktalk until April-ish, will they of kept my details?

We've since moved so I doubt talktalk can contact us?


 
Posted : 23/10/2015 6:13 pm
Posts: 47
Free Member
 

We've just been moved to Fleur by Talk talk, I wonder whether they've had the same problem?


 
Posted : 23/10/2015 6:17 pm
Posts: 33967
Full Member
 

While I wouldn't touch TalkTalk with a barge pole, I have to say OMITN is single-handedly doing more for their customer-relations than any spokesman I've seen on TV! Well done, sir, chapeau! ๐Ÿ˜€


 
Posted : 23/10/2015 6:28 pm
 tn25
Posts: 0
Free Member
 

Ironic isn't it after I raised a complaint about scam calls in July and got this reply:-

Dear * ******,

Further to our recent telephone conversation, I am writing to confirm that we have received your complaint regarding the recent increase in scam calls and emails.

Please rest assured that your sensitive information such as date of birth, bank, or credit card details have not been accessed.

We understand that this may cause you to be concerned but we have taken all appropriate actions to stop this from happening again and would like to reiterate that fraudsters are unable to gain access to either your TalkTalk account or your bank account unless you give them access.

Protecting our customers' data is our top priority and we take this issue extremely seriously. We ask that you take extra care when anyone phones or emails you claiming to be from TalkTalk, or indeed any other organisation, asking for personal details.

We hope you will accept our sincere apologies for any distress this has caused and confirm that this is our full and final position regarding your complaint.


 
Posted : 23/10/2015 6:46 pm
Posts: 0
Free Member
 

As a business we work in this type of environment including PCI DSS (PAYMENT CARD INDUSTY DATA SECURITY STANDARD) "if" Talk Talk are compliant with PCI DSS and executing vulnerability scans ASV scans and Pen testing as well as managing file integrity and log managment then it would be difficult to hack anything unless someone has been very stupid - the question that customers should be asking is "if you are compliant with PCI how did this happen" - there are a lot of "compliant" organisations, well they did fill in an SAQ (self assessment questionnaire) stating they are compliant


 
Posted : 23/10/2015 7:03 pm
Posts: 0
Free Member
 

Some reports that's it's a Islamic Cyber Jihadi attack emanating from the Soviet Union. Seem to be related to the website publishing supposed customer details


 
Posted : 23/10/2015 7:11 pm
Posts: 0
Free Member
 

Not really important who did what, the problem is few businesses take data protection seriously and the ones that do are usually made to do it via financial penalty (ICO PCI DSS etc ) the combination of name address date of birth bank details card details is identity theft heaven and despite what the credit reference agencies say it will take at least six years before you recover from it


 
Posted : 23/10/2015 7:18 pm
Posts: 13594
Free Member
 

There is no system which can't be hacked by a determined and skilled individual.


 
Posted : 23/10/2015 7:23 pm
Posts: 0
Free Member
 

That is partially true but they need exploits and open doors and "internal" mismanagement


 
Posted : 23/10/2015 7:26 pm
Posts: 2783
Full Member
 

i hear TalkTalk IT operations are a bit of a nightmare to work for, I've been approached a couple of times about roles but they have a bit of a bad rep.

"Hey we run a can attitude fast paced environment"
aka
"The guys are over worked/under funded and constantly forced to release shit that clearly isnt production ready"

As long as guys responsible for driving things into the ground get a decent bonus and are able to move on a gut another company its okay I suppose, its the suckers left holding the can that have to clean up the shitstorm.


 
Posted : 23/10/2015 8:17 pm
Posts: 0
Free Member
 

Some reports that's it's a Islamic Cyber Jihadi attack emanating from the Soviet Union. Seem to be related to the website publishing supposed customer details

Blimey - an attack across time and space!


 
Posted : 23/10/2015 8:50 pm
Posts: 341
Free Member
 

2 weeks ago lost all internet, numerous calls to a o847 number and pressing numours keys on the instructions of a recorded voice or saying what i wanted got through to people who cant understand english and apologise and say they will help sadly their idea of help is not any related idea of help i could understand, like throwing a heavy weight to a drowning man.

Eventually they agreed to send out a new router, and all worked well but still getting calls asking if i want to close my complaint which i dont till i get some sence out them, and now the hack, they dont know, yet 2 weks ago they said there was a major outage of their system and it would last 48 hours, next day they denied it.

They are also refusing people to break their contracts according to their website as their share plunge, they dont answer the phones,and a chap on a bike forum tells us more than their boss tells us customers.


 
Posted : 23/10/2015 9:18 pm
Posts: 2783
Full Member
 

IANAL but.....surely they've already broke the contract by failing to follow quite clear database protection policies.


 
Posted : 23/10/2015 10:18 pm
Posts: 2423
Free Member
 

SQL injection vulnerability & sensitive data stored in plain text in 2015? It defies understanding!


 
Posted : 23/10/2015 10:32 pm
Page 1 / 2