← Case Files · The Breach Files
TalkTalk, 2015: a nineteen-year-old and a webpage nobody owned
- People affected
- 156,959 customers, including 15,656 bank account numbers
- When it happened
- 15 – 21 October 2015
- Made public
- 22 October 2015
- How they got in
- SQL injection against legacy webpages inherited from the Tiscali UK acquisition
- Attributed to
- A group of UK teenagers; several were convicted, the eldest sentenced to four years
- What it cost
- £400,000 ICO fine, then a record; TalkTalk put the incident's cost at around £42 million and lost 101,000 customers
What was exposed: Names · Addresses · Dates of birth · Email addresses · Phone numbers · TalkTalk account information · Bank account numbers and sort codes
In October 2015 the chief executive of TalkTalk went on national radio and was asked whether the stolen customer data had been encrypted. She said she did not know. That answer, more than the breach, is what the incident is remembered for in Britain — and the technical story underneath it is worse, because the way in had been sitting unattended on the company's own website for six years.
What happened
TalkTalk acquired Tiscali UK in 2009. Along with the customers came the infrastructure, including a set of webpages that continued to be served from TalkTalk's domain. Three of those pages contained a SQL injection vulnerability. The underlying database software was unsupported and had been for years. After the acquisition, nobody at TalkTalk had scanned, reviewed or apparently thought about those pages at all.
Between 15 and 21 October 2015, attackers found them — trivially, using automated scanning tools available to anyone — and used the injection flaw to read data out of the database behind them. The ICO later found that the vulnerability could have been fixed with a software update that had been available since 2012, and that TalkTalk had no process that would have found it.
The regulator also established that two earlier attacks on the same pages, in July and September 2015, had gone unnoticed.
The inherited estate problem. Every acquisition transfers systems that nobody in the buying company designed, documented or wants to own. They keep running because turning them off requires knowing what they do. They keep being served because a DNS record points at them. Years later they are outside every inventory, outside every patch cycle, and still on the public internet under the parent company's name. TalkTalk is the canonical example, but the pattern is close to universal in any company that has grown by acquisition.
The disclosure made it worse
TalkTalk announced the breach quickly, which was to its credit, and then described it in terms it could not support. Early statements raised the possibility that all four million customers were affected. Reports referred to a "significant and sustained cyberattack", language that implied a sophisticated adversary. The eventual attackers were teenagers using off-the-shelf tools against a fifteen-year-old class of vulnerability.
The confusion over encryption compounded it. Some fields were encrypted, some were not, and in the first days the company could not say clearly which. For customers deciding whether to change bank details, that distinction was the only thing that mattered, and they could not get it.
Then came the fraud calls. Criminals with a customer's name, address, TalkTalk account number and in some cases bank details could open a phone call with verification data no stranger should have. Several victims reported losing substantial sums to callers who had been able to prove, convincingly, that they were TalkTalk.
The timeline
- 2009 — TalkTalk acquires Tiscali UK, inheriting the webpages that will later be attacked.
- 2012 — A fix for the underlying database vulnerability becomes available and is not applied.
- July and September 2015 — Two earlier attacks exploit the same pages without being detected.
- 15 – 21 October 2015 — The main attack extracts customer data.
- 22 October 2015 — TalkTalk goes public, with figures that later prove much too high.
- October – November 2015 — Several arrests follow; customers report fraud calls using their stolen details.
- 5 October 2016 — The ICO fines TalkTalk £400,000, the largest penalty it had ever issued.
- August 2017 — A further £100,000 fine follows over call centre staff access to 21,000 customers' records.
- 2019 — Daniel Kelley is sentenced to four years.
What it changed
It became the case study for UK regulators and parliament. A Commons select committee ran an inquiry into the protection of personal data online off the back of it, and its recommendations — escalating fines, security as a board responsibility, clearer breach notification — fed directly into how GDPR was received in Britain two years later.
The £400,000 fine established a ceiling that was about to disappear. It was the maximum the ICO could then issue, and commentators noted repeatedly that under GDPR the same conduct could attract a penalty measured in percentage of turnover. That comparison did a great deal to get UK boards to take the incoming regulation seriously.
Asset inventory stopped being a paperwork exercise. TalkTalk lost 156,959 customers' data through pages it did not know it was serving. "What is on our public internet estate, and who owns each thing on it" became a first-order security question, and the external attack surface scanning industry grew out of exactly this problem.
The cost of the response dwarfed the fine. The £400,000 penalty is the number everyone remembers. TalkTalk's own reporting put the incident's cost at around £42 million and the company lost 101,000 customers in the following quarter. For a consumer business, the regulator is rarely the expensive part.
If you were affected
- Treat any call that already knows your account details as unverified. Knowing your account number proves the caller has data, not that they work for the company. Hang up and dial the number on your bill.
- A sort code and account number are not secrets. They are printed on cheques. If someone treats them as proof of identity, that is a weakness in their process, not evidence that your account is compromised.
- Set a passphrase on telecoms and utility accounts where offered. It is the one control that defeats a caller holding your leaked details.
- Date of birth and address do not expire. A 2015 leak still furnishes the answers to security questions being asked in 2026, which is a good reason to answer those questions with something other than the truth.
Questions people ask
What is SQL injection?
It is what happens when a website takes something you typed and hands it to its database as an instruction instead of as text. Type an ordinary word into a search box and you get results; type carefully chosen punctuation and database commands and, on a vulnerable site, the database runs them. It has been documented since 1998 and it is comprehensively preventable, which is why finding it in a live system in 2015 was so damaging to TalkTalk's case.
How much data was actually taken from TalkTalk?
The final ICO finding was 156,959 customers' personal data, including 15,656 bank account numbers and sort codes. The first public figures were far higher and far vaguer — early reporting and TalkTalk's own initial statements raised the possibility that all four million customers were affected, which turned out to be wrong.
Were TalkTalk customers' bank accounts emptied?
There were reports of fraud against TalkTalk customers, but the sort code and account number alone do not let someone take money out — they are printed on every cheque. The more serious risk was what followed: criminals used the stolen account details and TalkTalk account references to make cold calls that sounded exactly like a real support call, which is a far more effective route to a bank transfer than the raw data ever was.
Did anyone go to prison for the TalkTalk hack?
Several young men were convicted. Daniel Kelley, who was seventeen at the time of the offences, was sentenced in 2019 to four years in a young offender institution for blackmail and computer misuse across a series of attacks. Others received shorter sentences and community orders. The individuals who found the flaw were not a sophisticated organised group, which was part of the point the regulator made.
Sources
- Information Commissioner's Office — monetary penalty notice, TalkTalk Telecom Group plc, October 2016
- House of Commons Culture, Media and Sport Committee — Cyber Security: Protection of Personal Data Online, 2016
- ICO monetary penalty, TalkTalk, 2017 — a further £100,000 over call centre access to 21,000 customers' data
- TalkTalk Telecom Group financial results, FY2016
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.