UK Telecomms firm TalkTalk has been breached again, but this time they are warning that financial and personal details of 4 Million customers have been exposed.

Widespread coverage today suggests that an orchestrated attack took place and, according to the BBC,

The following customer data, not all of which was encrypted, had been accessed:

  • Names and addresses
  • Dates of birth
  • Email addresses
  • Telephone numbers
  • TalkTalk account information
  • Credit card and bank details"

TalkTalk has suffered previous breaches which for many will erode any sympathy and benefit of the doubt when hearing of this latest attack. Are they careless and ignorant with respect to information security, or unlucky and victimized? Maybe somewhere in between?

A harsh assessment is that there are only two reasons why an organization like TalkTalk gets breached - underinvestment in security defense technology and cutting corners in the operation of security best practices.

Calling this a "significant and sustained cyber-attack" makes this titanic breach sound forgivable and understandable, in other words, 'How can anyone blame us for getting caught?'

But even at this early stage, the reported details suggest that mistakes have been made. Not just the previous breaches, but other reports suggest that weak certificates were still being used on their website - TalkTalk start to look like an organization that doesn't 'get' contemporary information security and the need for technology and security best practices.

The range of cyber attack weaponry is so vast and constantly evolving that 100% security is impossible, and organizations need to start thinking now in terms of Breach Detection: 'How will we know when we do suffer a breach, and what will we do when it happens?'

Getting an idea of the answers to these questions is just as crucial as putting defense measures and security best practices in place, especially if you are in charge of the bank details of 4 million trusting customers.

** UPDATE - 26 October 2015 - TalkTalk now report the following

"This cyber attack was on our website, not our core systems, We can confirm that we do not store complete credit card details on the website; any credit card details that may have been accessed had a series of numbers hidden and therefore are not usable for financial transactions eg 012345xxxxxx 6789

TalkTalk My Account passwords have not been accessed, We now expect the amount of financial information that may have been accessed to be materially lower than initially believed and would on its own not enable a criminal to take money from your account. The Metropolitan Police Cyber Crime Unit criminal investigation continues"



Read more at the BBC website

Read more at TalkTalk breach SCMagazine

Read more on TalkTalk breach at



The Most Powerful & Reliable Cybersecurity Products
Contact Us

USA Offices

New Net Technologies LLC
4850 Tamiami Trail, Suite 301
Naples, Florida, 34103

New Net Technologies LLC
1175 Peachtree St NE
Atlanta, Georgia, 30361.

Tel: (844) 898-8358
[email protected]


UK Office

New Net Technologies Ltd
The Russell Building, West Common
Harpenden, Hertfordshire

Tel: 020 3917 4995
 [email protected]

SC Magazine Cybersecurity 500 CSGEA Winners 2021 CIS benchmarking SEWP Sans Institute Now Certified IBM Security
Copyright 2021, New Net Technologies LLC. All rights reserved. 
NNT and Change Tracker are registered trademarks of New Net Technologies LLC.
All other product, company names and trademarks are the property of their respective owners.