Hackers 'steal TalkTalk customers' Wi-Fi router passwords'

But TalkTalk says no personal data is at risk and customers shouldn't change passwords

TalkTalk customers' Wi-Fi passwords may have been stolen following last week's Mirai cyber attack, which took 500,000 Post Office and TalkTalk routers offline, it has been claimed.

The first wave of the attack saw routers recruited into a massive botnet, which led to the initial outage. But according to Pen Test Partners security researcher Ken Munro, the attack is far more pernicious than that.

Information including the passwords, plus where the routers are being used, was uncovered by hackers who could now potentially break into the vulnerable D-Link DSL-3780 routers. However, TalkTalk denies this is the case.

The routers were hit by the Mirai malware last week, which took TalkTalk and the Post Office's broadband networks down. However, it is a follow up attack that leads the routers to reveal their passwords and Service Set Identifier (SSID) code, which reveals where the router is being used.

Advertisement
Advertisement - Article continues below

Despite Munro calling for the routers to be recalled, TalkTalk said it wasn't necessary because the company has implemented additional security procedures. What's more, its own security team "does not believe there is any greater risk that a customer's wi-fi can be used or accessed without their permission as a result of this".

"As is widely known, the Mirai worm is an industry issue, affecting many ISPs [internet service providers] around the world. A small number of TalkTalk customers have been affected, but we can reassure customers that no personal information is at risk," a spokeswoman said in a statement emailed to IT Pro.

Munro told BBC News that around 55,000 routers were likely affected, but TalkTalk said it is unlikely to be anywhere near that figure.

"If customers have an issue connecting to the internet, they should visit our help site where they can find a guide that will show them how to reset their router. There is no need for customers to reset their wifi password," the spokeswoman added.

However, Munro said a fix on TalkTalk's side was unlikely to solve the issue, and that the only way to safeguard against criminals breaking into routers and stealing information passing through a customer's home network was for TalkTalk to send out new routers to everyone affected, with a new password.

"We continue to take steps to review any potential impacts and have deployed a variety of solutions to ensure customers' routers remain safe. We have also employed additional network-level controls to further protect our customers," the firm said in a statement to the BBC.

Featured Resources

The essential guide to cloud-based backup and disaster recovery

Support business continuity by building a holistic emergency plan

Download now

Trends in modern data protection

A comprehensive view of the data protection landscape

Download now

How do vulnerabilities get into software?

90% of security incidents result from exploits against defects in software

Download now

Delivering the future of work - now

The CIO’s guide to building the unified digital workspace for today’s hybrid and multi-cloud strategies.

Download now
Advertisement

Recommended

Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/cloud/amazon-web-services-aws/354223/what-to-expect-from-aws-reinvent-2019
Amazon Web Services (AWS)

What to expect from AWS Re:Invent 2019

29 Nov 2019
Visit/hardware/354232/raspberry-pi-4-owners-complain-of-broken-wi-fi-when-using-hdmi
Hardware

Raspberry Pi 4 owners complain of broken Wi-Fi when using HDMI

29 Nov 2019
Visit/mobile/google-android/354189/samsung-galaxy-a90-5g-review-simply-the-best-value-5g-phone
Google Android

Samsung Galaxy A90 5G review: Simply the best value 5G phone

22 Nov 2019