Supply chain
β Supply Chain
TalkTalk Third-Party Breach (January 2025)
Primary Source βIncident Details
TalkTalk investigates breach after data for sale on hacking forum. UK telecommunications company TalkTalk is investigating a third-party supplier data breach after a threat actor began selling alleged customer data on a hacking forum. “As part of our regular security monitoring, given our ongoing focus on protecting customers’ personal data, we were made aware of unexpected access to, and misuse of, one of our third-party supplier’s systems, however, no billing or financial information was stored on this system,” TalkTalk told BleepingComputer. “Our Security Incident Response team are continuing to work with the supplier regarding this matter and protective containment steps were taken immediately.”. Third-party company: CSG Ascendon.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- CSG Ascendon
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-01-01 Breach occurred
- 2025-01-25 Publicly disclosed