By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
TechgoonduTechgoonduTechgoondu
  • Audio-visual
  • Enterprise
    • Software
    • Cybersecurity
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
    • Cellphones
    • Tablets
  • PC
  • Telecom
Search
© 2023 Goondu Media Pte Ltd. All Rights Reserved.
Reading: What caused the data leak at StarHub, the latest telco to get hit?
Share
Font ResizerAa
TechgoonduTechgoondu
Font ResizerAa
  • Audio-visual
  • Enterprise
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
  • PC
  • Telecom
Search
  • Audio-visual
  • Enterprise
    • Software
    • Cybersecurity
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
    • Cellphones
    • Tablets
  • PC
  • Telecom
Follow US
© 2023 Goondu Media Pte Ltd. All Rights Reserved.
Techgoondu > Blog > Cybersecurity > What caused the data leak at StarHub, the latest telco to get hit?
Cybersecurity

What caused the data leak at StarHub, the latest telco to get hit?

Alfred Siew
Last updated: September 11, 2021 at 10:20 AM
Alfred Siew
Published: August 10, 2021
5 Min Read
SHARE
  • PHOTO: Wilson Wong for Techgoondu.

The latest high-profile victim of a data leak in Singapore, StarHub seemed to have its bases covered when it revealed the unfortunate incident last Friday, just before a National Day long weekend.

The exposure of IC numbers, mobile numbers and e-mail addresses of more than 57,000 customers was detected online, as part of its security team’s surveillance efforts.

No credit card or bank account information is at risk and none of its information systems or customer database has been compromised, it said.

The telecom operator is also doing the right thing by offering credit monitoring service for free for six months through the Credit Bureau Singapore, so if you are notified by StarHub, you can check if your credit has been affected.

What is missing, perhaps, is the “how” of the story. While it is commendable that StarHub has been clear about what was exposed and taken proactive action, the worrying part is how the data was leaked.

If it is sure that none of its systems were compromised, how has the data been exfiltrated and posted online?

To be fair, StarHub has promised to safeguard customer information, by engaging a team of digital forensic and security experts and reviewing security measures, for example.

That said, finding the cause of a data leak quickly is important so that the telco knows where to plug the loophole and prevent more data from being stolen.

It can and should carefully monitor suspicious outbound data traffic and analyse patterns for data exfiltration but ultimately, it has to spend the effort to find and prevent a further leak from the same vulnerability.

A data leak could be due to a variety of factors. An attack from the outside is one common reason, but less usual incidents have involved insider attacks, for example.

StarHub should share its findings with its customers transparently, as its head honcho Nikhil Eapen promised last week. This is critical to winning back trust.

The timing and urgency that the telco shows in this endeavour will also help customers determine if it is a responsible, trustworthy company to do business with.

When rival Singtel got hit by a supply chain cyberattack in February, it took just two days from the time a data leak was established to going public with the news.

StarHub found its customer data posted online on July 6 but took a month to reveal this, preferring to bring in the experts and looking to remove the data from a data dump site.

Every incident is different but you wonder if StarHub could have announced the incident earlier and provided the remedial action, such as the credit monitoring service, afterwards.

It does look better prepared with its current response but then it’s spent a month to work on fixing the leak before announcing it. StarHub, a critical infrastructure provider, might wish to consider putting the information out earlier.

What damage could IC numbers, e-mail addresses or phone numbers cause, you might ask.

Well, think of hackers trying to get into your e-mail by trying out different passwords – once in, they can get control of your other linked accounts, like Amazon, Netflix or Facebook.

Or your phone numbers, proven to be legitimate ones now, might be spammed with calls and messages.

So, it matters that efforts to mitigate a damaging data breach are timely, transparent and useful to victims who are affected by it.

If you’re a StarHub customer who’s affected, do get on the credit monitoring service. Look out for attempts to log in to your e-mail accounts and be vigilant of any suspicious activities online.

StarHub unveils Android TV box with its StarHub Go video streaming app
Commentary: SingTel playing a risky game with its pay-TV stance
DJI Neo review: Clever drone for beginner pilots
New guidelines to keep the cloud from crashing Singapore’s digital infrastructure
Commentary: SingTel risks losing football fans with its pay-TV game
TAGGED:cybersecuritydata leakSingaporeStarHub

Sign up for the TG newsletter

Never miss anything again. Get the latest news and analysis in your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Whatsapp Whatsapp LinkedIn Copy Link Print
Avatar photo
ByAlfred Siew
Follow:
Alfred is a writer, speaker and media instructor who has covered the telecom, media and technology scene for more than 20 years. Previously the technology correspondent for The Straits Times, he now edits the Techgoondu.com blog and runs his own technology and media consultancy.
Previous Article Goondu review: The Forgotten City
Next Article Q&A: Supply chain attacks still rare but pose tough problem, says FireEye Mandiant
Leave a Comment

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

FacebookLike
XFollow

Latest News

Scammers are so successful they even accidentally scam themselves now
Cybersecurity Internet
June 10, 2025
Doom: The Dark Ages review: Future fantastic demon slaying
Gaming
June 10, 2025
Plaud NotePin review: Note-taking made easy with AI
Internet Mobile
June 9, 2025
Can smart grocery carts, biometric payments boost retailers like FairPrice?
Enterprise Internet
June 6, 2025

Techgoondu.com is published by Goondu Media Pte Ltd, a company registered and based in Singapore.

.

Started in June 2008 by technology journalists and ex-journalists in Singapore who share a common love for all things geeky and digital, the site now includes segments on personal computing, enterprise IT and Internet culture.

banner banner
Everyday DIY
PC needs fixing? Get your hands on with the latest tech tips
READ ON
banner banner
Leaders Q&A
What tomorrow looks like to those at the leading edge today
FIND OUT
banner banner
Advertise with us
Discover unique access and impact with TG custom content
SHOW ME

 

 

POWERED BY READYSPACE
The Techgoondu website is powered by and managed by Readyspace Web Hosting.

TechgoonduTechgoondu
© 2024 Goondu Media Pte Ltd. All Rights Reserved | Privacy | Terms of Use | Advertise | About Us | Contact
Join Us!
Never miss anything again. Get the latest news and analysis in your inbox.

Zero spam, Unsubscribe at any time.
 

Loading Comments...
 

    Welcome Back!

    Sign in to your account

    Username or Email Address
    Password

    Lost your password?