Taranaki Daily News

130,000 Xtra email addresses ‘at risk’

- TOM PULLAR-STRECKER

Spark says informatio­n from 130,000 Xtra email addresses is ‘‘at risk’’ as a result of a massive hack on Yahoo in 2014 that only came to light last week.

Privacy Commission­er John Edwards praised Spark but questioned Yahoo’s response and said the hack showed the need for a New Zealand law to force companies to own up to data breaches.

Yahoo said last week that 500 million email customers had informatio­n stolen in the attack which it believed had the backing of a foreign government.

The attack also affected Spark customers as it outsourced its Xtra email service to Yahoo in 2007.

Spark said about 15 per cent of its 825,000 Xtra email addresses were at risk.

The informatio­n stolen from Yahoo includes unencrypte­d questions and answers to security questions that could be used to reset account passwords.

These are commonly answers to questions such as a pet’s name or the name of people’s first school or car.

The leak of that informatio­n could cause customers’ other online services to be hijacked, in cases where they had supplied the same informatio­n.

Spark spokeswoma­n Michelle Baguley said it would be asking affected customers to immediatel­y change their passwords, if they hadn’t already.

At least the majority of impacted Xtra customers had not had unencrypte­d security questions and answers stolen, although there might be scenarios in which it had been, she said.

Yahoo had told Spark it had no evi- dence that the stolen informatio­n had been used to gain unauthoris­ed access to Spark accounts – meaning their actual emails – she said.

Edwards said he was monitoring the Yahoo hack. He did not believe it was acceptable that security questions and answers were stored unencrypte­d by Yahoo and he expected that would be an issue privacy investigat­ors in the United States and Ireland would look into.

‘‘We will be following those investigat­ions closely on behalf of New Zealanders.’’

The problem with such informatio­n was that, unlike passwords, it could often not be changed, he agreed.

‘‘Your mother’s maiden name remains your mother’s maiden name – there is nothing you can do to change that. These kinds of ‘prompts’ are not good enough any more I think.’’

Edwards said he was grateful that Spark quickly alerted his office and immediatel­y began taking action.

‘‘The fact that Yahoo may have known about the breach for a number of months before alerting the public shows why we need mandatory breach notificati­on.’’

The Government signalled in 2012 that it intended to introduce a law that would force companies to promptly disclose serious data breaches but this has not yet been implemente­d.

 ?? PHOTO: DAVID WHITE/FAIRFAX NZ ?? Privacy Commission­er John Edwards says ‘‘most’’ Xtra customers will not have had unencrypte­d answers to security questions stolen.
PHOTO: DAVID WHITE/FAIRFAX NZ Privacy Commission­er John Edwards says ‘‘most’’ Xtra customers will not have had unencrypte­d answers to security questions stolen.

Newspapers in English

Newspapers from New Zealand