On 22 October 2015 UK broadband and phone provider TalkTalk disclosed a cyber attack on its website. The company later confirmed that personal data belonging to 156,959 customers had been accessed, and that 15,656 of those customers also had their bank account numbers and sort codes stolen.
What happened
- The attackers used SQL injection, a well-understood technique, against outdated web pages that TalkTalk had inherited when it acquired another business. The attack ran from 15 to 21 October 2015.
- Police arrested several people, most of them teenagers or young men, and some were later convicted.
- In February 2016 TalkTalk reported that the attack had cost around £60 million and that it had lost around 101,000 customers.
- The House of Commons Culture, Media and Sport Committee opened an inquiry into cyber security and the protection of personal data online. It questioned chief executive Dido Harding on 15 December 2015.
Why it mattered
This was one of the most visible UK breaches of its time, and it put the costs and the reputational damage of a basic web vulnerability in front of boards. The ICO later fined the company for security failings.
Lessons for organisations
Organisations should keep an inventory of all their internet-facing systems, including those that come with an acquisition, and test them regularly for common flaws such as SQL injection. Incident communications should also be planned in advance.
Sources: ICO, Tech Monitor
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.