{"id":13233,"date":"2016-11-21T09:24:08","date_gmt":"2016-11-21T09:24:08","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=13233"},"modified":"2016-11-21T09:24:08","modified_gmt":"2016-11-21T09:24:08","slug":"darkmatter-analysis-uk-telecom-provider-3-hacked","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2016\/11\/21\/darkmatter-analysis-uk-telecom-provider-3-hacked\/","title":{"rendered":"DarkMatter analysis: UK telecom provider &#8216;3&#8217; hacked"},"content":{"rendered":"<p class=\"p1\"><span class=\"s1\">On November 18, 2016, UK mobile operator <\/span><span class=\"s2\"><em>Three<\/em> admitted millions of its customers\u2019 private information was at risk after hackers broke into its security system. <\/span><span class=\"s3\">The company said hackers used an employee login to access its customer upgrade database, leaving nine million customers at risk.<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\">A spokesman for Three detailed that over the last four weeks, the company had experienced an increasing level of attempted handset fraud. This had been visible through higher levels of burglaries of retail stores and attempts to unlawfully intercept upgrade devices. In order to commit this type of upgrade handset fraud, Three acknowledged that perpetrators used authorised logins to its upgrade system.<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\">The hackers then accessed customer accounts and upgraded them in order to intercept the new phones and sell them on.\u00a0<\/span><\/p>\n<p class=\"p2\"><span class=\"s3\"><b>DarkMatter commentary and insights<\/b><\/span><\/p>\n<p class=\"p2\"><span class=\"s3\">Three only discovered the breach, which occurred on the evening of November 17, 2016, after customers filed complaints claiming that scam callers were attempting to gain access to their bank accounts.\u00a0<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\">The fact that internal monitoring did not detect there may have been suspicious activity with respect to the functioning of the upgrade system is a shortcoming. In many ways we believe the insider threat looms larger than outsider threat given organisations typically shore up their defences tailored to mitigating threats emanating from outside of the organisation ahead of vetting and securing internal procedures, processes, and people.<\/span><\/p>\n<p class=\"p1\"><span class=\"s4\">DarkMatter believes insider threats need to be regarded and considered with the same rigour as external ones, and that<\/span> <span class=\"s3\">multi-factor authentication with diligent asset management of authentication tokens ought to be implemented, particularly in the case of retailers that manage inventories of physical or virtual assets.<\/span><\/p>\n<p class=\"p2\"><span class=\"s3\">Organisations need to re-visit their system of logon credentials, with the view to implementing multi-factor authentication to accounts, so that even if a password is stolen and access to a system gained, hackers cannot access any accounts or transactions without the corresponding token or biometric for the account.<\/span><\/p>\n<p class=\"p2\"><span class=\"s1\">We applaud the UK\u2019s <\/span><span class=\"s3\">Chancellor of the Exchequer, who has been especially vocal on matters related to the threat cyber crime poses to the British economy and indeed the welfare of regular people, and the requirement to actively defend against it. In his latest comment earlier this month he stated, &#8220;Trust in the internet and the infrastructure on which it relies is fundamental to our economic future. Because without that trust, faith in the whole digital edifice will fall away.&#8221;<\/span><\/p>\n<p class=\"p2\"><span class=\"s3\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On November 18, 2016, UK mobile operator Three admitted millions of its customers\u2019 private information was at risk after hackers broke into its security system. The company said hackers used an employee login to access its customer upgrade database, leaving nine million customers at risk. A spokesman for Three detailed that over the last four [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":13239,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,389],"tags":[1832,138,1416,2922],"class_list":["post-13233","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-telecom","tag-cyber-attack","tag-cyber-security","tag-darkmatter","tag-three"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/13233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=13233"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/13233\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/13239"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=13233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=13233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=13233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}