HomeSecurityTalkTalk investigates data breach allegations

TalkTalk investigates data breach allegations

British telecoms company TalkTalk is investigating a data breach (at a supplier). Someone is claiming to be selling customer data on a hacking forum.

TalkTalk data breach

“As part of our regular security monitoring and given our ongoing focus on protecting customer privacy, we are checking for unexpected access and misuse of one of our third-party supplier systems. However, there was no billing information or financial data stored on this system,” TalkTalk told BleepingComputer.

The company said its security incident response is working with the supplier to investigate the incident and measures have been taken to mitigate any potential consequences.

See also: OneBlood: Ransomware attack led to data breach

“Our investigations are ongoing, however we can confirm that the number of customers mentioned in some online posts is completely inaccurate“.

This statement comes after someone using the name “b0nd” began selling data that supposedly belonged to TalkTalk customers. The data breach reportedly took place in January.

“As the headline says today, we will be listing for sale relating to TalkTalk affects 18,839,551 current and past customers,” the post on the hacking forum states.

A sample of the data has even been published, which includes a subscriber's name, email, last used IP address, business phone number, and home phone number. Hackers often publish a small sample to show that the stolen data is valid.

However, while the post says the stolen data contains information on nearly 18.9 million current and former TalkTalk customers, the company probably doesn't even have that many subscribers, calling into question the authenticity of the data breach.

See also: North Korean hackers behind the Phemex breach?

Furthermore, screenshots published by the attacker indicate that the data was likely stolen from the Ascendon SaaS and not directly from TalkTalk.

CSG Ascendon is a subscription management platform used by TalkTalk. CSG confirmed that the data came from its platform , but said that its systems were not breached and that only one customer was affected.

“On January 21, 2025, CSG learned that an external user gained unauthorized access to data from an individual provider residing on a CSG platform,” CSG told BleepingComputer.

“We have no evidence that technologies and systems were compromised or that CSG was the cause of the unexpected data access. CSG provided immediate containment and is actively supporting the customer.“.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Although in the case of TalkTalk, a supplier and not the company itself was breached, telecoms providers must take steps to prevent potential attacks.

See also: Mission Bank: Is RansomHub behind the data breach?

Telecommunications companies: Protecting networks from cyberattacks

Telecommunications companies can protect their networks from cyberattacks by taking some protective measures.

The first and perhaps most critical step is education. Attacks are increasing in frequency and complexity, so it's important for everyone in the company to be informed and understand the risk. Regular training and seminars can help provide this information. Employees should learn the signs of a phishing attack and other tactics used by attackers.

TalkTalk investigates data breach allegations

Regularly updating and upgrading software and devices is another important measure to prevent cyberattacks. Out-of-date systems are more vulnerable to attacks.

Next, companies need to use advanced systems security. These systems include intrusion detection and intrusion prevention, and the use of reliable antivirus software is also important.

Additionally, companies can use encryption to protect data transmitted over their networks. Encryption converts data into a form that can only be decoded with a special key.

Telecom companies can also implement access policies to limit who can access networks . This can include requiring access credentials, two-factor authentication, and monitoring user behavior.

Using a firewall and VPN can also be very useful, as well as creating backups to restore stolen or locked files.

Finally, network segmentation is necessary so that an attack cannot spread to all of a company's systems.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS