Virgin media been hacked

mikew

Suspended / Banned
Messages
5,548
Name
mike
Edit My Images
Yes
Just got this email from them


Dear Mike, We are very sorry to have to inform you that we recently became aware that some of your personal information, stored on one of our databases has been accessed without permission. Our investigation is ongoing but we currently understand that the database was accessible from at least 19 April 2019 and that the information has been recently accessed.

To reassure you, the database did NOT include any of your passwords or financial details, such as bank account number or credit card information.

The database was used to manage information about our existing and potential customers in relation to some of our marketing activities. This included: contact details (such as name, home and email address and phone numbers), technical and product information, including any requests you may have made to us using forms on our website. In a very small number of cases, it included date of birth. Please note that this is all of the types of information in the database, but not all of this information may have related to you.

We take our responsibility to protect your personal information seriously. We know what happened, why it happened and as soon as we became aware we immediately shut down access to the database and launched a full independent forensic investigation. We have also informed the Information Commissioner’s Office.

Given the nature of the information involved, there is a risk you might be targeted for phishing attempts, fraud or nuisance marketing communications. We understand that you will be concerned so we are writing to everybody affected to provide reassurance, guidance and support. We have put all of the latest information on our website https://www.virginmedia.com/help/data-incident, including some advice on how to stay safe online, such as:
• Advice from the Information Commissioner's Office on how you can avoid or report nuisance marketing calls, emails and texts (https://ico.org.uk/)

• How to be vigilant by not providing your personal information to anyone suspicious online, by phone, email or text. If you want more information, you can get it here https://www.getsafeonline.org/protecting-yourself/spam-and-scam-email/

• How you can protect yourself from the risk of identity theft (which is when someone uses someone else’s personal information to obtain goods, services or money without permission) and other types of fraud. The Information Commissioner’s Office has information online here https://ico.org.uk/your-data-matters/identity-theft/
Although no financial, banking details or account passwords were accessed, it is always a good idea to make sure that your passwords are strong and not easy to guess. There is some advice here on how to set a strong password https://www.virginmedia.com/help/how-to-create-a-strong-password. If having read this email and visited our website you still have questions, you can contact us on 0800 052 2621, but please be aware our customer service advisors do not have any further information at this stage. Once again, we sincerely apologise for what has happened. Signature.png Lutz Schueler CEO, Virgin Media
 
Mine didn't use my name

Hello, We are very sorry to have to inform you that we recently became aware that some of your personal information, stored on one of our databases has been accessed without permission. Our investigation is ongoing but we currently understand that the database was accessible from at least 19 April 2019 and that the information has been recently accessed.

To reassure you, the database did NOT include any of your passwords or financial details, such as bank account number or credit card information.

The database was used to manage information about our existing and potential customers in relation to some of our marketing activities. This included: contact details (such as name, home and email address and phone numbers), technical and product information, including any requests you may have made to us using forms on our website. In a very small number of cases, it included date of birth. Please note that this is all of the types of information in the database, but not all of this information may have related to you.

We take our responsibility to protect your personal information seriously. We know what happened, why it happened and as soon as we became aware we immediately shut down access to the database and launched a full independent forensic investigation. We have also informed the Information Commissioner’s Office.

Given the nature of the information involved, there is a risk you might be targeted for phishing attempts, fraud or nuisance marketing communications. We understand that you will be concerned so we are writing to everybody affected to provide reassurance, guidance and support. We have put all of the latest information on our website https://www.virginmedia.com/help/data-incident, including some advice on how to stay safe online, such as:
• Advice from the Information Commissioner's Office on how you can avoid or report nuisance marketing calls, emails and texts (https://ico.org.uk/)

• How to be vigilant by not providing your personal information to anyone suspicious online, by phone, email or text. If you want more information, you can get it here https://www.getsafeonline.org/protecting-yourself/spam-and-scam-email/

• How you can protect yourself from the risk of identity theft (which is when someone uses someone else’s personal information to obtain goods, services or money without permission) and other types of fraud. The Information Commissioner’s Office has information online here https://ico.org.uk/your-data-matters/identity-theft/
Although no financial, banking details or account passwords were accessed, it is always a good idea to make sure that your passwords are strong and not easy to guess. There is some advice here on how to set a strong password https://www.virginmedia.com/help/how-to-create-a-strong-password. If having read this email and visited our website you still have questions, you can contact us on 0800 052 2621, but please be aware our customer service advisors do not have any further information at this stage. Once again, we sincerely apologise for what has happened. signature.png Lutz Schueler CEO, Virgin Media
 
Wonder if we can claim compensation? Not been a customer of theirs for ages so they should have deleted all the marketing contact. Think I opted out but can't prove it.
 
Wonder if we can claim compensation? Not been a customer of theirs for ages so they should have deleted all the marketing contact. Think I opted out but can't prove it.

Not sure but if GDPR controls are retrospective, on the surmise that you ceased being a customer before it came in, then I think they could have been in breach of GDPR to have retained your info without your explicit consent!

Perhaps at the very least see if the Data Commissioner (wracks brains, still called that ~ is it covered by the ICO?) has a consumer reporting system for ceased customers???
 
Wonder if we can claim compensation? Not been a customer of theirs for ages so they should have deleted all the marketing contact. Think I opted out but can't prove it.
Can you quantify your loss? That would be the first question you would need to answer in the "can I claim compensation" process.
 
Can you quantify your loss? That would be the first question you would need to answer in the "can I claim compensation" process.

It's impossible to quantify as you don't know what some nefarious person could use the information for. I don't know exactly what info was stolen. All these thefts lead to lots more spam and more risk of identity theft as they can join up bits of info they know via other bits they've stolen.

Should the damages be punitive to encourage companies to take information security more seriously?
 
If there is to be punishment it will be imposed in the form of a fine by the ICO in the data controller, and the data subjects won't see any of it.

Exemplary damages beyond compensation for quantifiable losses awarded to a claimant are only imposed in very limited circumstances in UK law and while I'm not a lawyer, I'm not aware of the being awarded for negligence or for other inadvertent losses and they definitely aren't available for breach of contract.
 
Back
Top