{"id":295030,"date":"2019-02-06T14:13:44","date_gmt":"2019-02-06T12:13:44","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=295030"},"modified":"2019-02-07T16:51:20","modified_gmt":"2019-02-07T14:51:20","slug":"eskom-data-leak-exposes-sensitive-customer-information-security-researcher","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/energy\/295030-eskom-data-leak-exposes-sensitive-customer-information-security-researcher.html","title":{"rendered":"Eskom data leak exposes sensitive customer information &#8211; Security researcher"},"content":{"rendered":"<p>Security researcher Devin Stokes has <strong><a href=\"https:\/\/twitter.com\/DevinStokes\/status\/1092847629497708545\" target=\"_blank\" rel=\"noopener\">disclosed<\/a><\/strong> a vulnerability in Eskom\u2019s information systems that is leaking customer data.<\/p>\n<p>Stokes said that he took the decision to go public after Eskom failed to respond to several disclosure emails, emails from news organisations, and direct messages on Twitter.<\/p>\n<p>He said that the leak has been going on for weeks.<\/p>\n<p>\u201cYou need to remove this data from the public view! You are unnecessarily exposing your customers data!\u201d said Stokes.<\/p>\n<p>In a follow-up tweet, Stokes posted a screenshot of a customer record in a live database, which showed the person\u2019s full name and credit card CVV. This has been blurred out in our screenshot.<\/p>\n<p>Information on what is causing the leak, or how the customer data was accessed, was not disclosed by the researcher.<\/p>\n<p>Queried about the leak, Eskom said that its group IT department is conducting investigations to determine whether sensitive Eskom information was compromised.<\/p>\n<p>&#8220;We will comment fully once the investigation is concluded,&#8221; Eskom said.<\/p>\n<h3 class=\"my-4\">Update &#8211; Eskom comment<\/h3>\n<p>Eskom\u2019s Acting Chief Information Officer, Nondumiso Zibi, said the server and \u201cMongo\u201d database in question does not belong to Eskom &#8211; and it is not hosted on its network.<\/p>\n<p>\u201cWe have traced it and can confirm that it is hosted in the US,\u201d said Zibi.<\/p>\n<p>\u201cWe have managed to trace the company responsible for this server and the database. The company is very co-operative and has since confirmed that the server has been shut down.\u201d<\/p>\n<p>Notwithstanding this, Eskom\u2019s Group Information Technology team is\u00a0conducting further investigations to determine whether the data in question is valid and belongs to Eskom customers, said the company.<\/p>\n<p><a  data-lightbox=\"post-image\" href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2019\/02\/Eskom-data-leak-2019-02Feb.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-295032\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2019\/02\/Eskom-data-leak-2019-02Feb.jpg\" alt=\"Eskom data leak 2019-02Feb\" width=\"585\" height=\"390\" \/><\/a><\/p>\n<h3 class=\"my-4\">Malware installation<\/h3>\n<p>News that an Eskom customer databases is leaking sensitive data comes after a security researcher from the MalwareMustDie security research work group reported that an Eskom employee\u00a0<a href=\"https:\/\/mybroadband.co.za\/news\/security\/295008-hacker-warns-eskom-about-malware-that-stole-a-users-company-credentials.html\"><strong>downloaded a trojan onto her computer<\/strong><\/a>.<\/p>\n<p>According to the researcher, the employee downloaded a fake Sims 4 installer &#8211; which resulted in her company credentials being compromised.<\/p>\n<p>Eskom did not confirm the details of the infection, but later thanked the hacker on Twitter, stating that the issue had been investigated and the necessary action taken.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/Eskom_SA?ref_src=twsrc%5Etfw\">@Eskom_SA<\/a> You don&#39;t respond to several disclosure emails, email from journalistic entities, or twitter DMs, but how about a public tweet? This is going on for weeks here. You need to remove this data from the public view!<\/p>\n<p>You are unnecessarily exposing YOUR customers data! <a href=\"https:\/\/t.co\/MgAOWrRv8o\">pic.twitter.com\/MgAOWrRv8o<\/a><\/p>\n<p>&mdash; stoXe (@DevinStokes) <a href=\"https:\/\/twitter.com\/DevinStokes\/status\/1092847629497708545?ref_src=twsrc%5Etfw\">February 5, 2019<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/295008-hacker-warns-eskom-about-malware-that-stole-a-users-company-credentials.html\">Hacker warns Eskom about malware that stole a user\u2019s company credentials<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Security researcher Devin Stokes has disclosed a vulnerability in Eskom\u2019s information systems that is leaking customer data.<\/p>\n","protected":false},"author":15,"featured_media":117208,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27995],"tags":[57254,181,35],"class_list":["post-295030","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-energy","tag-devin-stokes","tag-eskom","tag-headline"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/295030"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=295030"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/295030\/revisions"}],"predecessor-version":[{"id":295034,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/295030\/revisions\/295034"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/117208"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=295030"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=295030"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=295030"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}