We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

TalkTalk Hacking

2456

Comments

  • colsten
    colsten Posts: 17,597 Forumite
    10,000 Posts Seventh Anniversary Photogenic Name Dropper
    masonic wrote: »
    Yes, card details were amongst the things reported to have been compromised, although I believe organisations are not supposed to store the cv number.

    The 24/10/2015 3:30pm update from Talk Talk states that "We now expect the amount of financial information that may have been accessed to be materially lower than initially believed and would on its own not enable a criminal to take money from your account"
    http://help2.talktalk.co.uk/oct22incident

    Although you may argue that you don't believe anything Talk Talk are now saying. In which case, you should already have asked your bank to cancel your card - did you do that, RADDERS?
  • Westie983
    Westie983 Posts: 5,215 Forumite
    Tenth Anniversary 1,000 Posts I've been Money Tipped! Name Dropper
    colsten wrote: »
    Although you may argue that you don't believe anything Talk Talk are now saying. In which case, you should already have asked your bank to cancel your card - did you do that, RADDERS?

    Unless you change your bank account the detail TalkTalk have are your sort code and A/c number which wont change if you cancel the card, the PAN number and expiry date change.
    I’m a Forum Ambassador and I support the Forum Team on the Banking & Borrowing, and Reduce Debt & Boost Income boards. If you need any help on these boards, do let me know. Please note that Ambassadors are not moderators. Any posts you spot in breach of the Forum Rules should be reported via the report button, or by emailing forumteam@moneysavingexpert.com. All views are my own and not the official line of MoneySaving Expert.
    Save 12k in 2023 #58 Total (£4500.00) £2500.00/£5000 = 50.00%
    Sealed Pot Challenge ~17 #24 Total (£55.00) £0.00/£500 = 0.00%
    Xmas 2023 £1 a Day #13 Total (£85.00) £344.00/£365 = 94.24%
    Virtual Sealed Pot #1 Total (£500) £550.00/£500 = 110.00%
    £2 Savers Club 2023 #17 Total (£25.00) £45/£300 = 15.00%
    The 365 1p Challenge 2023 #7 Total £656.19/£667.95 = 98.23%
    Total £4095.19/£7332.95 = 55.84%
  • masonic
    masonic Posts: 27,983 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    Westie983 wrote: »
    Unless you change your bank account the detail TalkTalk have are your sort code and A/c number which wont change if you cancel the card, the PAN number and expiry date change.
    Sort code and account number being exposed is much less of a problem than exposure of the card details, which TalkTalk also have if radders paid upfront for line rental. Of course, if the card number was incomplete, more work would need to be done to identify the missing digits.
  • masonic
    masonic Posts: 27,983 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    Malcnascar wrote: »
    Perhaps it's time I admitted to my self that I need some help with my passwords. I know a bit about password managers but have resisted looking in detail at what they can do, how they work and would they work for me and finally would a password managers leave me at greater risk to the so called hackers.
    If you are currently in a position where you are using weak passwords, or reusing the same password across lots of different sites, then a password manager would almost certainly offer a net benefit. In this case it doesn't seem that passwords were compromised, but if every site you visit has a unique password it will limit the fallout of data breaches like this considerably. Password managers will also autogenerate very strong passwords for you. Two options to consider would be Lastpass and Keepass, both of which are highly regarded. Lastpass stores an encrypted database of your passwords online, allowing synchronisation, but which you might not like for security reasons, whereas Keepass can be used with just a local password store.

    One other thing that is quite important is to enable two factor authentication on your primary email account. Many compromises involve the hacker gaining access to the email of a victim after a breach at some other site. If your email provider doesn't support two factor, change provider.
  • GingerBob_3
    GingerBob_3 Posts: 3,659 Forumite
    masonic wrote: »
    Yes, card details were amongst the things reported to have been compromised, although I believe organisations are not supposed to store the cv number.


    But lots of them do - Amazon, for example.
  • masonic
    masonic Posts: 27,983 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    GingerBob wrote: »
    But lots of them do - Amazon, for example.
    Are you sure about Amazon? They only ask for card number, name, expiration date and billing address when you add a new one. I'm not sure I've ever provided them with CVV2.
  • TadleyBaggie
    TadleyBaggie Posts: 6,751 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    masonic wrote: »
    Are you sure about Amazon? They only ask for card number, name, expiration date and billing address when you add a new one. I'm not sure I've ever provided them with CVV2.
    You are correct, when I added a new card recently I was not asked for the CVV2 number.
  • Goldiegirl
    Goldiegirl Posts: 8,806 Forumite
    Part of the Furniture 1,000 Posts Rampant Recycler Hung up my suit!
    I think it comes down to who you want to believe


    The media or Talk Talk.


    I know I don't believe half or what I read in the media, so I come down in favour of believing Talk Talk. (I speak as a Talk Talk customer).


    Talk Talk had no reason to lie about anything that they said - they came out in the open and said that there'd been a data breach - and knew they'd get a hell of a lot of adverse publicity.


    Whereas the media have played on people's ignorance and fear and have every reason to manipulate and twist the facts to improve their ratings and sales. It seems they have been successful in whipping a portion of the British public into a frenzy of paranoia and indignation.


    I can't say I'm delighted that a Russian Islamist (or whoever is responsible) may have my sorting code and account number.


    But, I feel it is unlikely that he or she is going to trawl through 4 million peoples details to set up a direct debit on my account.


    And just in case he does, I'll be keeping an eye on my account for new direct debits that have been set up. If, on the off chance, he sets up a direct debit..... I'd cancel it straight away.


    If I forgot to look, and money was taken.... I'd be protected under the Direct Debit guarantee.


    People really need to calm themselves down and look at things rationally. Be vigilant and check your financial affairs daily. Be very wary of phishing attempts.


    Also, don't believe everything you read in the papers, particularly the Mail on Sunday!
    Early retired - 18th December 2014
    If your dreams don't scare you, they're not big enough
  • GingerBob_3
    GingerBob_3 Posts: 3,659 Forumite
    masonic wrote: »
    Are you sure about Amazon? They only ask for card number, name, expiration date and billing address when you add a new one. I'm not sure I've ever provided them with CVV2.


    You could be right. However, a couple of days ago I renewed card details with Books Etc, and they did ask for the CVV. Maybe this is just to validate the card and they then ask for it when you order - I can't remember.


    If Amazon don't ever request this info, either when signing up or when ordering, one must ask what use this code is - given that Amazon operate a "OneClick" ordering facility.
  • Futuristic
    Futuristic Posts: 1,223 Forumite
    Tenth Anniversary 1,000 Posts Photogenic Name Dropper
    edited 25 October 2015 at 4:28PM
    Talktalk confirmed full credit card details were not stored in their database as such if you pay via card you will be safe, you now need to ignore any calls pretending to be talk talk to get your data or send money to some scammers

    Your bank details if you pay via direct debit could be used to set up direct debits on another site to take money from your account, charities etc don't really have fail proof mechanism as sites just ask for bank account details such as name, acc number and sort code

    All end users can do is monitor their accounts as they should be doing regularly anyways
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.2K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 600.9K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.