Feeds

Sun compo entrants' privates exposed in public

Hacker posts Pastebin pasting

Internet Security Threat Report 2014

Security lapses at News International have exposed the email addresses and other personal information of readers who entered competitions in The Sun, the UK's biggest selling daily newspaper.

The names, addresses, phone numbers and dates of birth of thousands of people were also exposed by the hack, reckoned to have probably taken place at the same time that The Sun's website was hacked last month to redirect surfers towards a fictitious story on the supposed death of media mogul Rupert Murdoch.

Some of the data, including applications for the Miss Scotland beauty contest, has already been posted online. Entrants to a Wrigleys football competition, an Xbox competition, details of royal wedding well-wishers, and information from a forum for bullied people was also uploaded to Pastebin, The Guardian reports.

The data was uploaded by an individual called Batteye, who praised the actions of Anonymous as a whole and LulzSec, the hacktivist sub-group that returned from semi-retirement to carry out the 19 July Sun redirection hack. His rationale for exposing the private data of individuals in order to get at News Corp can be found here.

News International, publishers of The Sun and the firm currently in the middle of an ongoing phone and (now) computer hacking scandal, is reportedly going to contact affected individuals directly. Meanwhile the firm has reported the breach to both the police and the Information Commissioner, the BBC reports.

Miscreants could use the stolen information to mount targeting phishing scams. Neither financial information or passwords were exposed by the breach. Even so, News International ought to have encrypted personal data it holds, according to security firms, who said that the newspaper publisher had fallen well short of best practice.

"What this incident illustrates yet again is that consumer brands that we entrust our personal details must take their responsibilities much more seriously," said Mike Smart, EMEA product and solutions director at SafeNet. "While News International acknowledges financial details are secure as you would expect, the loss of so much unencrypted soft social data on names, addresses, emails and dates of birth offers a delicious feast of possibilities for scammers and spear-phishers."

Smart added: "With how their brand and reputation for trust has been so severely shaken, investing in proven and workable countermeasures like encryption to protect their readers seems an obvious step for News International to take." ®

Remote control for virtualized desktops

More from The Register

next story
UK smart meters arrive in 2020. Hackers have ALREADY found a flaw
Energy summit bods warned of free energy bonanza
DRUPAL-OPCALYPSE! Devs say best assume your CMS is owned
SQLi hole was hit hard, fast, and before most admins knew it needed patching
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Mozilla releases geolocating WiFi sniffer for Android
As if the civilians who never change access point passwords will ever opt out of this one
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Protecting against web application threats using SSL
SSL encryption can protect server‐to‐server communications, client devices, cloud resources, and other endpoints in order to help prevent the risk of data loss and losing customer trust.