Liberty SMS - Unauthorized access to IT infrastructure

There is no way they should pay one penny.

It's folly to think thieves and blackmailers will stick to their side of the deal.

Press speculation that some Liberty execs of thinking of paying is dismaying to say the least. Never deal with crooks.
 
This sort of thing has happened so many times before. Corporate companies are soft targets because they all have the same mentality, and lots of money. Instead of securing their network properly, they take the view that THEY will not be targeted, that sort of thing happens to other companies, not them. Now we just have to wait for them to release the industry standard statement that is "We take the security of our customers information very, very seriously" if they haven't already. Yeah, right. Who still listens and believes that crap? Anyway heads are going to have to roll and those whose do roll deserve it.
 
Dear Liberty

As it is my information you could not protect I would like to know the full extend of the breach.
 
"plain-text passwords"
Any Liberty software devs in here?
 
I wonder what they are running on their servers then, windows?
Out of curiosity to those running ms SQL servers do you have to run antivirus software as well? I've never faced that issue since we do Linux.

What does the OS or AV have to do with this?
 
I thought Liberty's main transactional platform was IBM hosts running some sort of System/370-derived OS and apps.

Reading between the lines, it appears unlikely that this is a simple ransomware infection. Rather, it seems to be a security breach where customer data has fallen into the hands of baddies, who now threaten to release customer data if they're not paid.

Trying to score a little Linux v Windows point is not just premature. It's entirely inappropriate. It doesn't seem to be a malware infection, so it can't be cured by restoring backups. The baddies have the data no matter what Liberty do.

This. More social engineering or poor security in the software and platform.
 
Ag nee seriously, read my post, before you get all triggered, I'm genuinely curious as to what they are running.

"unauthorised access to its IT infrastructure, by an external party who requested compensation for it."

Most of us immediately associated that with ransomware.

The ransom part is there but the ware part is not. With a typical ransomware attack the thieves don't get access to your data.
 
What does the OS or AV have to do with this?
Sigh did you actually read my post?
Since this looked like a data breach, possibly due to ransomware, I realized I have never thought of what server admins do on windows servers to keep them secure.
 
Sigh did you actually read my post?
Since this looked like a data breach, possibly due to ransomware, I realized I have never thought of what server admins do on windows servers to keep them secure.

I did, post above yours addresses that. No need for the sigh, it wasn't personal, it was a question.
 
Last edited:
[MENTION=463718]Newsfeed[/MENTION] can you ask Liberty for comment on whether their parent company Standard Bank and Stanlib have the same vulnerability and whether they store passwords in plain text?
 
[MENTION=463718]Newsfeed[/MENTION] can you ask Liberty for comment on whether their parent company Standard Bank and Stanlib have the same vulnerability and whether they store passwords in plain text?
Like they'd ever admit if they did
 
Like they'd ever admit if they did

Sure, but it's important for Standard Bank and Stanlib clients to realise that this may affect them by mere association. At the very least, Standard Bank would flat out deny it if it wasn't so. My next question would be "Why was Liberty's systems not secured then?". If the parent company wasn't interested in Liberty's state of affairs on the IT front... one would have assumed an audit at some point in the relationship.
 
Last edited:
This sort of thing has happened so many times before. Corporate companies are soft targets because they all have the same mentality, and lots of money. Instead of securing their network properly, they take the view that THEY will not be targeted, that sort of thing happens to other companies, not them. Now we just have to wait for them to release the industry standard statement that is "We take the security of our customers information very, very seriously" if they haven't already. Yeah, right. Who still listens and believes that crap? Anyway heads are going to have to roll and those whose do roll deserve it.

As big corporates, it's not that they don't care about IT security, in my experience they certainly do! The problem is that they view it as a box-checking exercise and they implement measures that do nothing but introduce red tape and inconvenience and serve mostly to ensure the employment of internal IT staff. Their policies are more focused on forcing users to reset their passwords every month than securing their web servers and encrypting confidential data in their databases.
 
Hackers want millions from Liberty, or will start releasing sensitive data – Report

According to a report in the Sunday Times on 17 June 2018, the hackers have demanded millions from Liberty.

The report stated the hackers have obtained “sensitive data” about “top clients”.
That leaves me out thankfully :p

"plain-text passwords"
Any Liberty software devs in here?

https://mybroadband.co.za/vb/member.php/437310-Jeruanamo
 
As big corporates, it's not that they don't care about IT security, in my experience they certainly do! The problem is that they view it as a box-checking exercise and they implement measures that do nothing but introduce red tape and inconvenience and serve mostly to ensure the employment of internal IT staff. Their policies are more focused on forcing users to reset their passwords every month than securing their web servers and encrypting confidential data in their databases.
This has been my experience as well.
 
"plain-text passwords"
Any Liberty software devs in here?

They will not be allowed to comment - and doing so could compromise their job. As much as I'd also love to know what's going on, please be considerate and don't encourage this.
 
They will not be allowed to comment - and doing so could compromise their job. As much as I'd also love to know what's going on, please be considerate and don't encourage this.

The question wasn't aimed at them. The only people who's jobs should be compromised is those in charge of the IT budget purse strings.
 
Just got same sms. Why send it to customers? Its their kuk to sort out.
They most likely have clients that are covered by Europe's GDPR. This will require them to come clean, or else they face massive penalties under GDPR.

Sure it is their mess to sort out, but it is also their responsibility to notify their clients.
 
Top
Sign up to the MyBroadband newsletter
X