The Press

Hack puts 130,000 addresses at risk

- TOM PULLAR-STRECKER

Spark says informatio­n from 130,000 Xtra email addresses is ‘‘at risk’’ as a result of a massive hack on Yahoo in 2014 that only came to light last week.

Privacy Commission­er John Edwards praised Spark but questioned Yahoo’s response and said the hack showed the need for a New Zealand law to force companies to own up to data breaches.

Yahoo said last week that 500 million email customers had informatio­n stolen in the attack which it believed had the backing of a foreign government.

The attack also affected Spark customers as it outsourced its Xtra email service to Yahoo in 2007.

Spark said about 15 per cent of its 825,000 Xtra email addresses were at risk.

The informatio­n stolen from Yahoo includes unencrypte­d questions and answers to security questions that could be used to reset account passwords. These are commonly answers to questions such as a pet’s name or the name of people’s first school or car.

The leak of that informatio­n could cause customers’ other online services to be hijacked, in cases where they had supplied the same informatio­n.

Spark spokeswoma­n Michelle Baguley said it would be asking affected customers to immediatel­y change their passwords.

At least the majority of impacted Xtra customers had not had unencrypte­d security questions and answers stolen, she said.

Yahoo had told Spark it had no evidence that the stolen informatio­n had been used to gain unauthoris­ed access to Spark accounts, meaning their actual emails, she said.

Edwards said he was monitoring the Yahoo hack.

He did not believe it was acceptable that security questions and answers were stored unencrypte­d by Yahoo and he expected that would be an issue privacy investigat­ors in the United States and Ireland would look into.

‘‘Your mother’s maiden name remains your mother’s maiden name – there is nothing you can do to change that. These kinds of ‘prompts’ are not good enough any more I think.’’

Edwards said he was grateful that Spark quickly alerted his office to the breach and immediatel­y began taking action to resolve it.

‘‘The fact that Yahoo may have known about the breach for a number of months before alerting the public shows why we need mandatory breach notificati­on,’’ he said.

The Government signalled in 2012 that it intended to introduce a law that would force companies to promptly disclose serious data breaches but it has not yet been implemente­d.

Justice Minister Amy Adams said she intended to introduce a new Privacy Bill to Parliament next year.

‘‘With significan­t informatio­n held offshore by companies like Yahoo, new measures will also address privacy concerns about cross-border informatio­n flows.’’

 ?? PHOTO: DAVID WHITE/FAIRFAX NZ ?? Privacy Commission­er John Edwards says ‘‘most’’ Xtra customers will not have had unencrypte­d answers to security questions stolen.
PHOTO: DAVID WHITE/FAIRFAX NZ Privacy Commission­er John Edwards says ‘‘most’’ Xtra customers will not have had unencrypte­d answers to security questions stolen.

Newspapers in English

Newspapers from New Zealand