UK telecommunications provider, TalkTalk, is currently investigating a potential data breach following claims made on a cybercrime forum. A threat actor, using the handle "b0nd," has alleged to possess the data of nearly 19 million current and former TalkTalk customers. The investigation is in its early stages and involves a third-party supplier whose platform is believed to manage a small part of the company’s customer base. This platform, however, does not store billing details or other sensitive financial information. TalkTalk has confirmed that they are aware of the posts and that an investigation is underway with the supplier, and that immediate protective measures have been taken.
The threat actor has claimed that the data includes subscriber PINs, names, email addresses, last account access information, IP addresses, and phone numbers. However, TalkTalk believes that the reported scale of the data breach is significantly overstated. They highlight that they have never had close to 19 million customers and that the platform involved only manages a subset of their total of around 2.4 million. The company is working with the third-party supplier to determine the validity of the claims but have stated no billing or financial data was held on the third party system. TalkTalk continues to prioritize the protection of customer data and is actively addressing this matter.