Liberty SMS - Unauthorized access to IT infrastructure

If you didnt saw the news .... Lilberty's IT system was hacked on Thursday night (but they say no confidential info was leaked, nor did anyone lose 1c )

L O L
 
Dear Valued Customer: We are conscious that that there has been an understandable level of interest and concern after we announced on Saturday that Liberty has been the victim of a criminal act. Our team of dedicated IT specialists and security personnel have devoted all their efforts around the clock to ensure that we live up to the duty of care to protect your information. We have made no concessions in the face of this attempted extortion and we are working with the relevant law enforcement authorities. We are at an advance stage of investigating the extent of the data breach, which at this stage seems to be largely emails and attachments. At this point there is no evidence that any customer has suffered any financial loss. Liberty will proactively inform any customer individually if and when it is discovered that they may have been impacted. Should you have any queries or concerns, contact our Call Centre on 0860 456 789 or email [email protected].


(sms received)
 
Last time I checked, Old Mutual emails were being transmitted unencrypted from a high site near my place. I'll check this week if it's still being done. I wonder if this is a similar breach.
 
“It’s fair to say an event like this is not something one can prepare for specifically,” said Munro.


Ostrich, sand, crocodile, tears.
 
It’s fair to say an event like this is not something one can prepare for specifically,” said Munro
Crap! Absolute trash. They are expected and the onus is solely on the company to minimise damage and losses.
 
“It’s fair to say an event like this is not something one can prepare for specifically,” said Munro.


Ostrich, sand, crocodile, tears.

Have you had experience with managing a very large organisation's IT security? Do you know exactly what happened here? If the answer is no to either of those questions then it is unnecessary to be so judgemental.
 
Have you had experience with managing a very large organisation's IT security? Do you know exactly what happened here? If the answer is no to either of those questions then it is unnecessary to be so judgemental.
+1 A man with knowledge, experience, and wisdom.

Those who think their systems are 100% secure just don't know about the holes.
 
Have you had experience with managing a very large organisation's IT security? Do you know exactly what happened here? If the answer is no to either of those questions then it is unnecessary to be so judgemental.

Yep, I have and I do.
The disconnect between the purse string holders , and the tech fellers who know what needs to be done, is astounding
 
I was pretty judgemental until I realised that they weren't in fact storing passwords in plain text. That was a mis-read of the article on my part. On the contrary I've swung towards an opinion that they did the absolute right thing by sending out the sms so early on. Kudos to them for that. I am keen to hear what the vulnerability was in fact and why they thought it was not something they could prepare for.
 
Yep, I have and I do.
The disconnect between the purse string holders , and the tech fellers who know what needs to be done, is astounding, in my experience

FTFY. There's not always a disconnect, there's just other things that money needs to be spent on, including the salaries of core business staff. Did you work for Liberty?
 
+1 A man with knowledge, experience, and wisdom.

Those who think their systems are 100% secure just don't know about the holes.

There is no such thing as a secure system when you have humans in charge.
 
FTFY. There's not always a disconnect, there's just other things that money needs to be spent on, including the salaries of core business staff. Did you work for Liberty?

No I don't work there.
But what irks me, is the initial denial from Liberty, as well as the fact, that this has been going on forever.
Like back in the day when we easily copied the SAM file and then showed the powers that be that their belief that their systems were "Ho ho ho, unbreakable" was a delusion.
For us to walk up to unsecured systems and be able to do these things, and then be told that measures to fix were way beyond budget, was mind boggling.

And yes salaries need to be paid, but to not implement best practices as well as vulnerability test on a regular basis, is insane in this day and age.

Now before I get flamed for "You don't know what went down at Liberty", well if you read yesterday's newspaper article, and read their initial denial, and sound bite of it could never happen to us, then I have no qualms about painting them with the same brush on security issues that have been plaguing large networks for so many years.
 
There is no such thing as a secure system when you have humans in charge.

No, but there is common sense like storing your data encrypted at rest.

Sucks for the people that use Liberty that they trusted their data to a bunch of monkeys.
 
No I don't work there.
But what irks me, is the initial denial from Liberty, as well as the fact, that this has been going on forever.
Like back in the day when we easily copied the SAM file and then showed the powers that be that their belief that their systems were "Ho ho ho, unbreakable" was a delusion.
For us to walk up to unsecured systems and be able to do these things, and then be told that measures to fix were way beyond budget, was mind boggling.
Can you elaborate for context - who is we? If you feel there's more to this story then please share.

And yes salaries need to be paid, but to not implement best practices as well as vulnerability test on a regular basis, is insane in this day and age.
As above, clearly you have inside info.

Now before I get flamed for "You don't know what went down at Liberty", well if you read yesterday's newspaper article, and read their initial denial, and sound bite of it could never happen to us, then I have no qualms about painting them with the same brush on security issues that have been plaguing large networks for so many years.
I must have missed those. Can you quote / link?
 
Top
Sign up to the MyBroadband newsletter
X