All the latest UK technology news, reviews and analysis

Powergen customer info exposed in net blunder

by John Leyden

19 Jul 2000

Be the first to comment

  • Tweet this

Utility firm PowerGen admitted today that it had suffered a breach of internet security which resulted in the leak of bank and contact details of thousands of its customers.

A PowerGen spokeswoman told vnunet.com today: "We found out late yesterday that there was a breach of security. We will be contacting customers whose data was accessed, and passing information to the police."

According to PowerGen, 2500 of its gas and electricity customers were affected by the security lapse. However, the customer who discovered the lapse, Leicester-based IT consultant John Chamberlain, said a far higher number of people were affected.

Chamberlain told the BBC how he accidentally discovered a file containing the names, addresses and banking card numbers of an estimated 7000 PowerGen customers when he tried to pay his bill online earlier this month.

"It took no special skills. I couldn't believe what I saw. It was basically names, addresses, credit card details, account numbers and so on," Chamberlain told the paper.

"I thought, 'I wonder if I'm in here', so I clicked the search button and typed in my name and off it went and found my name, address, credit card number, expiry date."

Paul Cronin, head of penetration testing at CenturyCom, said the problem at PowerGen was not an isolated incident and firms often failed to secure customer data, due to a variety of mistakes.

"We find that web connections left open at a firewall allow people to get into back-end databases. Poorly designed web applications and web servers not patched are other sources of problems," said Cronin. He added that security measures applied by hosting firms were often to blame for problems.

Frank Martin, senior security consultant, Siemens Network Systems, said: "PowerGen could have put the tools in place to expose any unauthorised attempts to access confidential customer information. It could have done more to protect unauthorised access to that information."

A Powergen spokeswoman said: "We take the security of customers' personal information very seriously."

She said that the website is secure and Powergen customers can now feel confident about using it.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Project Manager WAN SP Infrastructure M3 M4 Corridor

Prince 2 Project Management Professional, Client Facing...

solution architect

Solution Architect / Technical Project Manager / Corporate...

solution architect

Solution Architect / Technical Project Manager / Corporate...

Administrator - Global Corporate Actions

Tier 1 Investment Bank seeks an Administrator with an...

To send to more than one email address, simply separate each address with a comma.