Liberty SMS - Unauthorized access to IT infrastructure

Just got same sms. Why send it to customers? Its their kuk to sort out.

Transparency. Just appreciate it, because people moan when they aren't informed of such things and find out afterwards.
 
Liberty Life Hacked

Got this sms at 05h00 today.

Dear Valued Customer, Liberty regrets to inform you that it has been subjected to unauthorised access to its IT infrastructure, by an external party who requested compensation for it. Since becoming aware - we have taken immediate steps to secure our computer systems and are investigating the incident. We are giving this matter the highest priority and will keep you informed as appropriate.
 
Got this sms at 05h00 today.

Dear Valued Customer, Liberty regrets to inform you that it has been subjected to unauthorised access to its IT infrastructure, by an external party who requested compensation for it. Since becoming aware - we have taken immediate steps to secure our computer systems and are investigating the incident. We are giving this matter the highest priority and will keep you informed as appropriate.

There’s several threads on this already
 
This isn't a simple forum. This is life insurance, medical aid, retirement annuities and so on!
 
I wonder what they are running on their servers then, windows?
Out of curiosity to those running ms SQL servers do you have to run antivirus software as well? I've never faced that issue since we do Linux.
 
So what if the data gets leaked? We've had so many leaks already that I doubt there's anything worthwhile to share.

Maybe medical records?
 
I thought Liberty's main transactional platform was IBM hosts running some sort of System/370-derived OS and apps.

Reading between the lines, it appears unlikely that this is a simple ransomware infection. Rather, it seems to be a security breach where customer data has fallen into the hands of baddies, who now threaten to release customer data if they're not paid.

Trying to score a little Linux v Windows point is not just premature. It's entirely inappropriate. It doesn't seem to be a malware infection, so it can't be cured by restoring backups. The baddies have the data no matter what Liberty do.
 
Last edited:
A Liberty spokesperson told MyBroadband they are investigating the matter, and have secured their computer systems, but cannot provide more information to the media at this stage.
 
A Liberty spokesperson told MyBroadband they are investigating the matter, and have secured their computer systems, but cannot provide more information to the media at this stage.

I wonder how they secured it. Did they find the “hole” that quickly?
 
Inside job?
Not impossible. They have many external people with some or other degree of access to customer data. It could even be something as simple as an as-yet-unreported lost or stolen laptop where the user had access to customer data.

No SMS for me, probably because all my 30-year-old Liberty policies are matured, exercised, and paid out.
 
Ironically, the global regulatory obsession with gathering as much information as possible for financial transactions is only making this worse. Hard to believe, but in the era before FICA, most things could be accomplished with just an ID number and maybe an address, sometimes just your name. Now, financial institutes are required to maintain so much data on individuals, including information on where funds come from, etc etc, that it makes data breaches potentially so much worse.
 
Trying to score a little Linux v Windows point is not just premature. It's entirely inappropriate. It doesn't seem to be a malware infection, so it can't be cured by restoring backups. The baddies have the data no matter what Liberty do.

Ag nee seriously, read my post, before you get all triggered, I'm genuinely curious as to what they are running.

"unauthorised access to its IT infrastructure, by an external party who requested compensation for it."

Most of us immediately associated that with ransomware.
 
Sorry, didn't aim that at you specifically. My apols.

Of course we're interested in what systems they run, and how this breach happened. Your questions are entirely reasonable.
 
Sunday Times says personal data was stolen and the perpetrators are demanding money in exchange for not releasing the data.
 
Top
Sign up to the MyBroadband newsletter
X