Six million Sky broadband customers exposed to flaw that could let hackers steal bank info

19 November 2021, 15:55

Around six million Sky broadband customers were exposed to a security hack.
Around six million Sky broadband customers were exposed to a security hack. Picture: Alamy

By Sophie Barnett

Around six million Sky broadband customers were exposed to a security flaw that would have allowed hackers to "control millions of hubs for 18 months", a security company has warned.

Listen to this article

Loading audio...

The flaw has been fixed, but the security researchers said it took Sky nearly 18 months to fix the problem.

The bug was uncovered by the security group Pen Test Partners, who said it affected users who had not changed the router's default admin password.

As this is simple and easy to guess, hackers could easily reconfigure the router and take over a network, just by directing the user to a malicious network.

This could then give hackers access to sensitive information including log-in details for online banking.

According to the researchers, the affected router models were: Sky Hub 3 (ER110), Sky Hub 3.5 (ER115), Booster 3 (EE120), Sky Hub (SR101), Sky Hub (SR203), and the Booster 4 (SE210).

Sky said it had begun working to fix the problem as soon as it was made aware of it and it took the security of its customers "very seriously".

Cyber security expert explains what is behind the twitter hack

Pen Test Partners said there was no evidence the flaw had been exploited, but criticised Sky for the time it took to fix the issue.

It claimed the internet service provider had repeatedly pushed back deadlines it had set to fix the problem.

A spokesman for Sky said: "We take the safety and security of our customers very seriously.

"After being alerted to the risk, we began work on finding a remedy for the problem and we can confirm that a fix has been delivered to all Sky manufactured products."

The initial delay to the time it took for Sky to fix the problem was put down to the coronavirus pandemic, researchers said.

It also said it did not want to disrupt the "vastly increased network loading as working from home became the new norm".

But researchers were concerned by the speed - and time it took - for the company to respond, saying they believed Sky "did not give the patch the priority their customers deserved".

If you have a broadband router mentioned above, the research company has advised you change the passwords on it from the default ones set.

More Latest News

See more More Latest News

An eruption of Mount Ruang in the Sulawesi island, Indonesia, on Friday

More than 2,100 people evacuated as Indonesian volcano spews clouds of ash

Sabrina Carpenter took inspiration from THAT scene in Saltburn for her outro for her song 'Nonsense'

Sabrina Carpenter makes 'Saltburn' reference about boyfriend Barry Keoghan in 'Nonsense' outro at Coachella

Iranian officials say the attacks, in the central province of Isfahan, were caused by small exploding drones

Israeli airstrike on Iran downplayed as tensions ease between Tel Aviv and Tehran

Azzarello was pictured outside the courthouse a day earlier with a conspiracy sign

Man who set himself on fire outside Donald Trump's hush money trial has died, police confirm

Venezuela Ecuador Mexico

Venezuela’s main opposition bloc agrees on candidate to challenge Maduro

Azzarello was pictured outside the courthouse a day earlier with a conspiracy sign

'Researcher', 37, set himself on fire outside Donald Trump's hush money trial in shocking 'political protest'

Matt Healy's family have spoken out amid speculation that one of Taylor Swift's new songs is about him.

'Nothing surprises him anymore': Matt Healy's family break silence over claims new Taylor Swift tracks are about him

Geri Halliwell and Christian Horner are said to be in talks for a documentary

Geri Halliwell and Christian Horner 'in talks to make fly-on-the-wall documentary' following 'inappropriate behaviour' row

An officer threatened to arrest the man for 'breaching the peace'

Met police apologise again after 'victim blaming' backlash over threat to arrest 'openly Jewish' man at march

Donald Trump in court

Full jury of 12 and six alternatives selected in Donald Trump hush money trial

Trump Hush Money

Police to review security at Trump courthouse after man sets himself on fire

Donald Trump

Trump’s hush money case to go ahead after judge rejects latest bid to delay

Mark Menzies

Police reviewing claims Tory MP Mark Menzies misused campaign funds to 'pay off bad people'

Trump Hush Money

Man in critical condition after setting himself on fire outside Trump courthouse

Paramedics attended to a person who lit themselves on fire near Manhattan Criminal Court

Horror as man sets himself on fire outside Donald Trump's hush money trial in New York

Jonathan Hogg was attacked by the xl bully (stock image) in Leigh.

Father, 37, mauled to death by XL Bully had 'worst injuries doctor had seen' from 15-minute attack