Hackers 'steal TalkTalk customers' Wi-Fi router passwords'

But TalkTalk says no personal data is at risk and customers shouldn't change passwords

TalkTalk customers' Wi-Fi passwords may have been stolen following last week's Mirai cyber attack, which took 500,000 Post Office and TalkTalk routers offline, it has been claimed.

The first wave of the attack saw routers recruited into a massive botnet, which led to the initial outage. But according to Pen Test Partners security researcher Ken Munro, the attack is far more pernicious than that.

Advertisement - Article continues below

Information including the passwords, plus where the routers are being used, was uncovered by hackers who could now potentially break into the vulnerable D-Link DSL-3780 routers. However, TalkTalk denies this is the case.

The routers were hit by the Mirai malware last week, which took TalkTalk and the Post Office's broadband networks down. However, it is a follow up attack that leads the routers to reveal their passwords and Service Set Identifier (SSID) code, which reveals where the router is being used.

Despite Munro calling for the routers to be recalled, TalkTalk said it wasn't necessary because the company has implemented additional security procedures. What's more, its own security team "does not believe there is any greater risk that a customer's wi-fi can be used or accessed without their permission as a result of this".

Advertisement
Advertisement - Article continues below

"As is widely known, the Mirai worm is an industry issue, affecting many ISPs [internet service providers] around the world. A small number of TalkTalk customers have been affected, but we can reassure customers that no personal information is at risk," a spokeswoman said in a statement emailed to IT Pro.

Advertisement - Article continues below

Munro told BBC News that around 55,000 routers were likely affected, but TalkTalk said it is unlikely to be anywhere near that figure.

"If customers have an issue connecting to the internet, they should visit our help site where they can find a guide that will show them how to reset their router. There is no need for customers to reset their wifi password," the spokeswoman added.

However, Munro said a fix on TalkTalk's side was unlikely to solve the issue, and that the only way to safeguard against criminals breaking into routers and stealing information passing through a customer's home network was for TalkTalk to send out new routers to everyone affected, with a new password.

"We continue to take steps to review any potential impacts and have deployed a variety of solutions to ensure customers' routers remain safe. We have also employed additional network-level controls to further protect our customers," the firm said in a statement to the BBC.

Featured Resources

Preparing for long-term remote working after COVID-19

Learn how to safely and securely enable your remote workforce

Download now

Cloud vs on-premise storage: What’s right for you?

Key considerations driving document storage decisions for businesses

Download now

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Transforming productivity

Solutions that facilitate work at full speed

Download now
Advertisement

Recommended

Visit/security/ransomware/356292/university-of-california-gets-fleeced-by-hackers-for-114-million
ransomware

University of California gets fleeced by hackers for $1.14 million

30 Jun 2020
Visit/security/cyber-security/356289/australia-announces-135b-investment-in-cybersecurity
cyber security

Australia announces $1.35 billion investment in cyber security

30 Jun 2020
Visit/cloud/cloud-security/356288/csa-and-issa-form-cybersecurity-partnership
cloud security

CSA and ISSA form cyber security partnership

30 Jun 2020
Visit/business/policy-legislation/356215/senators-propose-a-bill-aimed-at-ending-warrant-proof-encryption
Policy & legislation

Senators propose a bill aimed at ending warrant-proof encryption

24 Jun 2020

Most Popular

Visit/business/business-operations/356395/nvidia-overtakes-intel-as-most-valuable-us-chipmaker
Business operations

Nvidia overtakes Intel as most valuable US chipmaker

9 Jul 2020
Visit/laptops/29190/how-to-find-ram-speed-size-and-type
Laptops

How to find RAM speed, size and type

24 Jun 2020
Visit/server-storage/servers/356083/the-best-server-solution-for-your-smb
Sponsored

The best server solution for your SMB

26 Jun 2020