ICO Looks Into BT E-Mail Data Breach Claims

The Information Commissioners’ Office has confirmed it is following up claims that BT exposed a number of its customers’ email accounts during the migration from Yahoo Mail to a white-label product from Critical Path, which has since been purchased by Openwave.

According to documents obtained by The Register, an anonymous whistleblower told the ICO that a large number of accounts had been compromised during the migration – it seems no login details were leaked, but the addresses were left on an open page where anyone could harvest them.

As a result, it appears from the documents  that BT customers’ email accounts were being spammed on a daily basis, that the company was most likely not meeting its requirements as part of the Data Protection Act, and was aware of this. It is unclear how many accounts might be affected by the alleged breach, but seven million users are being moved from the Yahoo-based platform to the new service.

BT data breach

BT WifiThe ICO has confirmed to TechWeekEurope that it has indeed contacted BT about the allegations: “On 13 March 2014 we wrote to BT with a number of questions. Our enquiries into this matter are still ongoing and no conclusions have yet been reached.”

BT also said it was aware of the regulator’s interest but stressed the alleged vulnerability had been discovered during testing and had been fixed.

“BT has been made aware by the ICO that they are conducting an unverified assessment in relation to BT Mail security, a service which is provided by Openwave (formerly Critical Path),” a BT spokesperson told TechWeekEurope. “BT takes the security of all products very seriously and, in the process of developing new services with partners, we rigorously audit and test for security, and fix any identified issues before going into live service.

“We believe this unverified assessment of BT Mail relates to an issue identified and fixed as part of our normal testing and development process.”

If the allegations are proved to be true, the ICO has the power to impose a significant fine on BT. Earlier this month, the British Pregnancy Advice Service (BPAS), a charity which helps women considering abortion, was fined £200,000 after a data breach revealed the names of 10,000 of its users to Anonymous hacker James Jeffery in March 2012.

Do you know the history of BT? Try our quiz!

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

Tencent Invests £1bn In Ubisoft Spin-Off

Ubisoft and Tencent to create new joint-venture developing some of company's highest-profile games, including Assassin's…

23 mins ago

NASA, Boeing To Begin Starliner Testing After ‘Anomalies’

American space agency prepares for testing of Boeing's Starliner, to ensure it has two space…

3 days ago

Meta Launches Friends Tab, As Zuck Touts ‘OG Facebook’

Zuckerberg seeks to revive Facebook's original spirit, as Meta launches Facebook Friends tab, so users…

3 days ago

WhatsApp Appeal Against EU Fine Backed By Court Advisor

Notable development for Meta, after appeal against 2021 WhatsApp privacy fine is backed by advisor…

4 days ago

Intel Board Shake-Up As Three Members Confirm Retirement

First sign of shake-up under new CEO Lip-Bu Tan? Three Intel board members confirm they…

4 days ago