Feeds

Sun compo entrants' privates exposed in public

Hacker posts Pastebin pasting

Beginner's guide to SSL certificates

Security lapses at News International have exposed the email addresses and other personal information of readers who entered competitions in The Sun, the UK's biggest selling daily newspaper.

The names, addresses, phone numbers and dates of birth of thousands of people were also exposed by the hack, reckoned to have probably taken place at the same time that The Sun's website was hacked last month to redirect surfers towards a fictitious story on the supposed death of media mogul Rupert Murdoch.

Some of the data, including applications for the Miss Scotland beauty contest, has already been posted online. Entrants to a Wrigleys football competition, an Xbox competition, details of royal wedding well-wishers, and information from a forum for bullied people was also uploaded to Pastebin, The Guardian reports.

The data was uploaded by an individual called Batteye, who praised the actions of Anonymous as a whole and LulzSec, the hacktivist sub-group that returned from semi-retirement to carry out the 19 July Sun redirection hack. His rationale for exposing the private data of individuals in order to get at News Corp can be found here.

News International, publishers of The Sun and the firm currently in the middle of an ongoing phone and (now) computer hacking scandal, is reportedly going to contact affected individuals directly. Meanwhile the firm has reported the breach to both the police and the Information Commissioner, the BBC reports.

Miscreants could use the stolen information to mount targeting phishing scams. Neither financial information or passwords were exposed by the breach. Even so, News International ought to have encrypted personal data it holds, according to security firms, who said that the newspaper publisher had fallen well short of best practice.

"What this incident illustrates yet again is that consumer brands that we entrust our personal details must take their responsibilities much more seriously," said Mike Smart, EMEA product and solutions director at SafeNet. "While News International acknowledges financial details are secure as you would expect, the loss of so much unencrypted soft social data on names, addresses, emails and dates of birth offers a delicious feast of possibilities for scammers and spear-phishers."

Smart added: "With how their brand and reputation for trust has been so severely shaken, investing in proven and workable countermeasures like encryption to protect their readers seems an obvious step for News International to take." ®

Remote control for virtualized desktops

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Choosing a cloud hosting partner with confidence
Download Choosing a Cloud Hosting Provider with Confidence to learn more about cloud computing - the new opportunities and new security challenges.