Categorized | AVG

Vodafone data leak – a long chain with several weak links

Hi folks,

On Jan 9th, the Sydney Morning Herald ran a very interesting story about millions of Vodafone customers having their data leaked.

The article is slightly misleading, albeit probably unintentionally, because on first reading it looks like _all_ four million Vodafone customers had their data leaked, but after reading it, and some related articles, it seems more likely that anyone’s data _could_ have been stolen, but it’s by no means clear whether we’re talking 100s or 1000s of accounts.

It’s still important, however, because criminal gangs are buying the leaked account details, which include credit cards and drivers’ license numbers.

The nub of the matter is that Vodaphone employees _and_ Vodafone dealers are given user ids and passwords that allow them to access the main user database. This makes sense, because they’d need to be able to see account details, so that they could provide support and sell upgrades, and for any number of legitimate reasons.

The problem is that any one of these passwords gives the password possessor full access to _all four million_ Vodafone accounts! And, not only that, but they can access it from anywhere on the Internet.

That makes these passwords extremely valuable to criminals and would-be criminals. I have no idea how many Vodafone employees and dealers there are, but the number is likely in the thousands. 

That’s an awful lot of potential targets for the Bad Guys. Put another way, everyone understands that a chain is only as strong as its weakest link, and that’s an awful long chain.

One’s mind wanders and wonders how many other businesses have a similar model, and therefore, how many other shoes are waiting to drop.

Keep safe folks,

Roger

 

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago