Skip to main content

Advice from the BBC re the TalkTalk hack:

 

Be wary if you receive any telephone calls claiming to be from TalkTalk, especially if the caller asks you for private information.

 

Be suspicious if an email relating to TalkTalk asks you to reply with personal information or click on a link. Criminals can set up official-looking websites to harvest your account details.

 

Look through your recent transactions for any payments you do not recognise, even if they are very small.

"People will try and take a small amount first. TalkTalk has four million customers. If they do four million ÂĢ1 transactions, that's not a bad haul," said Mr Dresner.

If you spot any unusual activity you should contact your bank and Action Fraud on 0300 123 2040.

 

TalkTalk is advising customers to change their account password as soon as its website is back up and running.

It is especially important to change your password on other websites, if you have used the same one across many accounts.

 

http://www.bbc.co.uk/news/technology-34615692

 

 

 

Replies sorted oldest to newest

Originally Posted by Garage Joe:

We have one of our land lines with TT. We pay by direct debit. I've tried to log into the site on and off but gave up.

Ditto  GJ .....but am not even going to try logging on at the moment ....especially as one news broadcast warned that the hackers might set up *spoof * sites to gain more info  

Baz
Last edited by Baz

FYI, just received my notification from TalkTalk:

 

 

 
Your TalkTalk account number: 0123456789
 
Dear Mr Eugene's Lair,
We are very sorry to tell you that on Thursday 22nd October a criminal investigation was launched by the Metropolitan Police Cyber Crime Unit following a significant and sustained cyberattack on our website on Wednesday 21st October. The investigation is ongoing, but unfortunately there is a chance that some of the following data may have been accessed:
 
â€ĒNames
â€ĒAddresses
â€ĒDate of birth
â€ĒPhone numbers
â€ĒEmail addresses
â€ĒTalkTalk account information
â€ĒCredit card details and/or bank details
 
We are continuing to work with leading cyber crime specialists and the Metropolitan Police to establish exactly what happened and the extent of any information accessed.
 
We would like to reassure you that we take any threat to the security of our customers’ data very seriously. We constantly review and update our systems to make sure they are as secure as possible and we’re taking all the necessary steps to understand this incident and to protect as best we can against similar attacks in future. Unfortunately cyber criminals are becoming increasingly sophisticated and attacks against companies which do business online are becoming more frequent.
What we are doing:   
 
â€ĒWe are contacting all our customers straight away to let them know what has happened and we will keep you up to date as we learn more.
 
â€ĒWe have taken all necessary measures to make our website secure again following the attack.
 
â€ĒTogether with cyber crime experts and the Metropolitan Police, we’re completing a thorough investigation.
 
â€ĒWe have contacted the Information Commissioner’s Office.
 
â€ĒWe’ve contacted the major banks, and they will be monitoring for any suspicious activity on our customers’ accounts.
 
â€ĒWe are looking to organise a year’s free credit monitoring for all of our customers and will be in touch on this in due course.
What you can do:  
 
â€ĒKeep an eye on your accounts over the next few months. If you see anything unusual, please contact your bank and Action Fraud as soon as possible. Action Fraud is the UK’s national fraud and internet crime reporting centre, and they can be reached on 0300 123 2040 or via http://www.actionfraud.police.uk
 
â€ĒIf you are contacted by anyone asking you for personal data or passwords (such as for your bank account), please take all steps to check the true identity of the organisation.
 
â€ĒChange the password for your TalkTalk account and any other accounts that use the same password.
 
â€ĒCheck your credit report with the three main credit agencies: Call Credit, Experian and Equifax. Noddle also allows free access to your credit report for life.
 
Please be aware, TalkTalk will NEVER call customers and ask you to provide bank details unless we have already had specific permission from you to do so.
 
TalkTalk will also NEVER:
 
â€ĒAsk for your bank details to process a refund. If you are ever due a refund from us, we would only be able to process this if your bank details are already registered on our systems.
 
â€ĒCall you and ask you to download software onto your computer, unless you have previously contacted TalkTalk and agreed a call back for this to take place.
 
â€ĒSend you emails asking you to provide your full password. We will only ever ask for two digits from it to protect your security.
We understand this will be concerning and frustrating, and we want to reassure you that we are continuing to take every action possible to keep your information safe. If you have any questions, please visit http://help2.talktalk.co.uk/oct22incident for more information, or you can call us on 0800 083 2710 or 0141 230 0707.
 
 
Yours sincerely,
 
TAHanison
Tristia Harrison Managing Director, Consumer
Eugene's Lair
Last edited by Eugene's Lair
FYI, here's the latest e-mail from TalkTalk:
 
 
 
Your TalkTalk account number: 0123456789
 
Dear Mr Eugene's Lair,
We know it’s been a worrying and frustrating time since Wednesday’s cyber attack on our website. We’re doing everything we can to get to the bottom of what happened as soon as possible and to keep you updated.   Our investigations are currently showing the following:
 
â€ĒThe number of customers affected and the amount of data potentially stolen is smaller than originally thought. Our website was attacked, but our core systems weren’t and remain secure.
 
â€ĒOn its own, none of the data that may have been accessed could be used to leave you financially worse off. 
 
â€ĒWe don’t store unencrypted credit or debit card data on our site, so any card details which may have been accessed have the 6 middle digits blanked out. For example, it would appear as 012345XXXXXX6789. This means it can’t be used for financial transactions.
 
â€ĒNo My Account passwords have been accessed.
 
â€ĒNo banking details were taken that you won’t already be sharing with people when you write a cheque or give to someone so they can pay money into your account.
 
 
We will continue investigating and promise to keep you updated as we know more.  In the meantime, we strongly encourage that you:
 
â€ĒSign up to your free credit reporting service using this code: TT231. We have partnered with Noddle, one of the leading credit reference agencies, to offer 12 months of credit monitoring alerts for all customers. You can find out more at www.talktalk.co.uk/secure.
 
â€ĒStay vigilant - TalkTalk will NEVER call customers and ask you to provide personal details or passwords. Please take all steps to check the true identity of any organisation that calls requesting personal information. If you have any doubts, please call us on 0800 083 2710 or 0141 230 0707.
We are sorry for the concern this week’s attack has caused, but want to reassure you that we are doing everything possible to keep your information safe.
For more information, please visit: www.talktalk.co.uk/secure.
 
 
Yours sincerely,
 
TAHanison
Tristia Harrison Managing Director, Consumer
Eugene's Lair

 

The Register has done an interesting "timeline" of the TalkTalk hack, highlighting the contradictory statements the company has made, and how little is yet known about what actually happened:

http://www.theregister.co.uk/2...t_management_review/

 

"The Register has contacted TalkTalk and made many enquiries regarding its security practices. We had not received any answer to our enquiries at the time of publication."

Eugene's Lair

Add Reply

×
×
×
×
Link copied to your clipboard.
×
×