Frame-14

Privacy Ninja

        • DATA PROTECTION

        • Email Spoofing Prevention
        • Check if your organization email is vulnerable to hackers and put a stop to it. Receive your free test today!
        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • AntiHACK Phone
        • Boost your smartphone’s security with enterprise-level encryption, designed by digital forensics and counterintelligence experts, guaranteeing absolute privacy for you and up to 31 others, plus a guest user, through exclusive access.

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$3,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Secure your digital frontiers with our API penetration testing service, meticulously designed to identify and fortify vulnerabilities, ensuring robust protection against cyber threats.

        • Network Penetration Testing
        • Strengthen your network’s defenses with our comprehensive penetration testing service, tailored to uncover and seal security gaps, safeguarding your infrastructure from cyber attacks.

        • Mobile Penetration Testing
        • Strengthen your network’s defenses with our comprehensive penetration testing service, tailored to uncover and seal security gaps, safeguarding your infrastructure from cyber attacks.

        • Web Penetration Testing
        • Fortify your web presence with our specialized web penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats.

        • RAPID DIGITALISATION

        • OTHERS

The Telegraph Exposes 10 TB Database With Subscriber Info

The Telegraph Exposes 10 TB Database With Subscriber Info

‘The Telegraph’, one of the UK’s largest newspapers and online media outlets, has leaked 10 TB of data after failing to properly secure one of its databases.

The exposed information includes internal logs, full subscriber names, email addresses, device info, URL requests, IP addresses, authentication tokens, and unique reader identifiers.

Bob Diachenko, the researcher who discovered the unprotected dataset on September 14, 2021, has confirmed that at least 1,200 unencrypted contacts were accessible without a password at the time of his review.

telegraph record
A sample of the exposed records. Source: cooltechzone.com

Notably, many of these cases concern registrant information of Apple News subscribers, also including passwords in plaintext form.

Also Read: Top 3 Simple Data Backup Singapore and Recovery Methods

The newspaper was contacted and warned about the exposure immediately, but it took them two days to eventually respond and secure the database.

The instance was indexed on specialized search engines on September 1, 2021, so the period of exposure is at least three weeks. That’s plenty of time for attackers and automated scanners to find the exposed database and exfiltrate the contained data.

Only affects a subset of subscribers

For those of you who might have been exposed as a result of this data leak, the main risk you’re running is getting scammed or phished via email.

The leak of the URL requests may also cause a privacy risk as someone could use them to construct the users’ browsing history on the news platform.

As for the consequences for The Telegraph, stolen access tokens could be used by non-subscribers to access content locked behind its paywall, but they could solve this with a reset. 

In response to the above, The Telegraph issued the following statement regarding Diachenko’s findings:

We became aware of this discovery on 16 September and took immediate action to secure the data. An investigation showed that only a small number of records were exposed – less than 0.1% of our users and we have contacted all the users to advise them. The investigation also concluded that whilst the data was exposed it was not breached other than the discovery posted by the researcher. We are grateful for the work of independent researchers who responsibly disclose vulnerabilities and exposures and who are vital in our continued work to protect our assets.

According to this statement, the number of the impacted individuals is 600, which is less than what Daichenko saw exposed. The Telegraph also states that none of them run any risks of exploitation since Diachenko was the first and last person to access the sensitive dataset.

Also Read: What is Pseudonymisation: 5 Techniques and Its Best Practices

Out of an abundance of caution, if you’re a subscriber to The Telegraph, we would suggest that you reset your password and remain vigilant against unsolicited emails that make bold claims or ask you to take urgent action to secure your account.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us