Virgin Media huge data breach
Author
Discussion

Jordan210

Original Poster:

5,152 posts

207 months

Thursday 5th March 2020
quotequote all
Virgin have suffered a huge data breach. See below for email sent to customers and non customers who virgin appeared to hold data for.


Hello,
We are very sorry to have to inform you that we recently became aware that some of your personal information, stored on one of our databases has been accessed without permission. Our investigation is ongoing but we currently understand that the database was accessible from at least 19 April 2019 and that the information has been recently accessed.

To reassure you, the database did NOT include any of your passwords or financial details, such as bank account number or credit card information.

The database was used to manage information about our existing and potential customers in relation to some of our marketing activities. This included: contact details (such as name, home and email address and phone numbers), technical and product information, including any requests you may have made to us using forms on our website. In a very small number of cases, it included date of birth. Please note that this is all of the types of information in the database, but not all of this information may have related to you.

We take our responsibility to protect your personal information seriously. We know what happened, why it happened and as soon as we became aware we immediately shut down access to the database and launched a full independent forensic investigation. We have also informed the Information Commissioner’s Office.

Given the nature of the information involved, there is a risk you might be targeted for phishing attempts, fraud or nuisance marketing communications. We understand that you will be concerned so we are writing to everybody affected to provide reassurance, guidance and support. We have put all of the latest information on our website https://www.virginmedia.com/help/data-incident, including some advice on how to stay safe online, such as:
• Advice from the Information Commissioner's Office on how you can avoid or report nuisance marketing calls, emails and texts (https://ico.org.uk/)
• How to be vigilant by not providing your personal information to anyone suspicious online, by phone, email or text. If you want more information, you can get it here https://www.getsafeonline.org/protecting-yourself/...
• How you can protect yourself from the risk of identity theft (which is when someone uses someone else’s personal information to obtain goods, services or money without permission) and other types of fraud. The Information Commissioner’s Office has information online here https://ico.org.uk/your-data-matters/identity-thef...
Although no financial, banking details or account passwords were accessed, it is always a good idea to make sure that your passwords are strong and not easy to guess. There is some advice here on how to set a strong password https://www.virginmedia.com/help/how-to-create-a-s...
If having read this email and visited our website you still have questions, you can contact us on 0800 052 2621, but please be aware our customer service advisors do not have any further information at this stage.
Once again, we sincerely apologise for what has happened.

Mr. E

832 posts

74 months

Thursday 5th March 2020
quotequote all
CRM
Available since last year
Hmmm I wonder

Sophisticated Sarah

15,078 posts

193 months

Thursday 5th March 2020
quotequote all
Not surprising. They outsourced a load of data sensitive jobs abroad a few years back rolleyes

Blib

47,301 posts

221 months

Thursday 5th March 2020
quotequote all
I received that email a little while ago.

slightlyoldgit

586 posts

224 months

Thursday 5th March 2020
quotequote all
Here is a thing...

Your email address, DOB and address might have been obtained.

Erm, so what?

55palfers

6,292 posts

188 months

Thursday 5th March 2020
quotequote all
https://www.dailymail.co.uk/sciencetech/article-80...

I like the way they are saying they have enough on their plates with Coronavirus at the moment!

The cock-up happened months ago.

Dynamic Space Wizard

958 posts

128 months

Thursday 5th March 2020
quotequote all
Jordan210 said:
Given the nature of the information involved, there is a risk you might be targeted for phishing attempts, fraud or nuisance marketing communications
Lol, that's them! They do that all the time anyway laugh

Mr E

22,732 posts

283 months

Thursday 5th March 2020
quotequote all
I have had the same email. I’d like to know exactly what information they exposed.

Mr. E said:
CRM
Available since last year
Hmmm I wonder
I got very confused by this. I didn’t recall writing it. smile

valiant

13,483 posts

184 months

Thursday 5th March 2020
quotequote all
slightlyoldgit said:
Here is a thing...

Your email address, DOB and address might have been obtained.

Erm, so what?
Don’t they have a duty to keep YOUR data safe?


Doofus

33,369 posts

197 months

Thursday 5th March 2020
quotequote all
We've had around 30 cold calls to our landline in the past week, compared to maybe 3 in the previous year. So far, we've had no communication from Viigin.

Drumroll

4,384 posts

144 months

Thursday 5th March 2020
quotequote all
Doofus said:
We've had around 30 cold calls to our landline in the past week, compared to maybe 3 in the previous year. So far, we've had no communication from Viigin.
We have also seen an increase in nuisance calls the last couple of weeks. Maybe Virgin could give us call blocker for free as a bit of compensation.

Mojooo

13,288 posts

204 months

Thursday 5th March 2020
quotequote all
slightlyoldgit said:
Here is a thing...

Your email address, DOB and address might have been obtained.

Erm, so what?
Apt username... but one example, very elderly may have their data sold to cold callers who may target them on the phone and in person to sell them rubbish.

bristolbaron

5,338 posts

236 months

Thursday 5th March 2020
quotequote all
Mr E said:
I have had the same email. I’d like to know exactly what information they exposed.

Mr. E said:
CRM
Available since last year
Hmmm I wonder
I got very confused by this. I didn’t recall writing it. smile
It’s a Mr. E mystery Mr E!

Halb

53,012 posts

207 months

Thursday 5th March 2020
quotequote all
Jasey_ said:
That email appears to have been written by a 10 year old !
same one that did their security you think?

eharding

14,648 posts

308 months

Thursday 5th March 2020
quotequote all
bristolbaron said:
Mr E said:
I have had the same email. I’d like to know exactly what information they exposed.

Mr. E said:
CRM
Available since last year
Hmmm I wonder
I got very confused by this. I didn’t recall writing it. smile
It’s a Mr. E mystery Mr E!
Slightly OT, but Google doesn't honour '.' characters in the local-part of @gmail.com addresses. I registered mine back in the mists of time, which does have '.' characters in the local-part, but it appears that various folk in the US still think their email address is differentiated from it. Hence I'm repeatedly signed up on the email list of a prayer group in Oregon, a Ford dealership in Texas, and have had a number of presumably confidential US tax and HR details from randoms who can't remember their email address properly sent through to me.

It's very odd. I assume these folk keep putting their variations of the address into various sites, never see a response, but keep doing so. The ones with obviously confidential details I respond to the admin pointing out the error, and generally never hear from them again.

I've given up trying to unsubscribe from the prayer group, and they keep sending me - or rather, the misspelled version of me - invocations to pray for generally elderly parishioners in Pendleton, Oregon who have invariably grim medical prognoses. Actually, I'm rather dreading that if this virus kicks off big time in the US quite how much praying might be requested.


Spare tyre

12,142 posts

154 months

Friday 6th March 2020
quotequote all
eharding said:
bristolbaron said:
Mr E said:
I have had the same email. I’d like to know exactly what information they exposed.

Mr. E said:
CRM
Available since last year
Hmmm I wonder
I got very confused by this. I didn’t recall writing it. smile
It’s a Mr. E mystery Mr E!
Slightly OT, but Google doesn't honour '.' characters in the local-part of @gmail.com addresses. I registered mine back in the mists of time, which does have '.' characters in the local-part, but it appears that various folk in the US still think their email address is differentiated from it. Hence I'm repeatedly signed up on the email list of a prayer group in Oregon, a Ford dealership in Texas, and have had a number of presumably confidential US tax and HR details from randoms who can't remember their email address properly sent through to me.

It's very odd. I assume these folk keep putting their variations of the address into various sites, never see a response, but keep doing so. The ones with obviously confidential details I respond to the admin pointing out the error, and generally never hear from them again.

I've given up trying to unsubscribe from the prayer group, and they keep sending me - or rather, the misspelled version of me - invocations to pray for generally elderly parishioners in Pendleton, Oregon who have invariably grim medical prognoses. Actually, I'm rather dreading that if this virus kicks off big time in the US quite how much praying might be requested.
Same, I get American
Car service
Dental appointment
Trades quotes
Etc

Email to a particular person all the time. Clearly not a scam as they are just dull info. If I’m feeling helpful I reply saying about their error

zygalski

7,759 posts

169 months

Friday 6th March 2020
quotequote all
Doofus said:
We've had around 30 cold calls to our landline in the past week, compared to maybe 3 in the previous year. So far, we've had no communication from Viigin.
Ditch the landline.
You won't regret it!

Riley Blue

23,012 posts

250 months

Friday 6th March 2020
quotequote all
Jasey_ said:
Indeed.

I particularly like "If having read this email and visited our website you still have questions, you can contact us on 0800 052 2621, but please be aware our customer service advisors do not have any further information at this stage."

If you are concerned give us a call and we wont be able to help any further.
The link to their website for further information results in, "Sorry, we can't find the page you're looking for!"

Doofus

33,369 posts

197 months

Friday 6th March 2020
quotequote all
zygalski said:
Doofus said:
We've had around 30 cold calls to our landline in the past week, compared to maybe 3 in the previous year. So far, we've had no communication from Viigin.
Ditch the landline.
You won't regret it!
My wife's dad is the only person to use it. He refuses to accept that a calling a mobile doesn't actually cost both parties.

All calls go straight to answerphone, including his, so it really isn't any kind of inconvenience to have a landline. Whilst I probably won't regret ditching it, I also suspect I will be entirely ambivalent if I were to do so.

Evercross

6,883 posts

88 months

Friday 6th March 2020
quotequote all
zygalski said:
Doofus said:
We've had around 30 cold calls to our landline in the past week, compared to maybe 3 in the previous year. So far, we've had no communication from Viigin.
Ditch the landline.
You won't regret it!
I suggested to the VM Customer Services person that I ditch the landline from my package as part of my contract renewal negotiation to save some cash. She informed me it would actually mean my monthlies would go up by £30.