About 600 of the 2000 ADSL clients received a letter today from Belgacom that they will have to reset and reprogram their ADSL connection because their accounts were published on a Belgian Server that used those lists to download stuff (probably all legal ?). The Investigative Team of Skynet discovered the lists in december and took immediate action. They contacted the Belgian persons responsable and asked to immediately withdraw those listings from the server. According to the letter a complaint was filed. It is illegal to use the logins from others to download stuff (also if he or she is having an open wireless link). They had no clue and were astonished that this was the case. After that all the information disappeared from the net and the culprits agreed not to use it, the information campaign was being set up and all the different actors in this campaign were being informed and trained. They are now responding to the calls for information and help. It is not yet clear how the logins themselves were collected by them. But it maybe a very interesting signal for the users that you will always have to secure your ADSL router or your wireless connection and that you should always have an antivirus and firewall on your desktop. We want also to recall that according to the Belgian New Telecom Law our ISP's should offer a free securitypackage to their clients, even if they say that it is enough to try to secure the parameters with firewalls and antivirus. It should now be clear that the free distribution of these securitypackages would only defend the use of EID but also their customers against such fraud-attacks. Imagine that someone now receives a letter that he or she is being sued for downloading illegal versions of media or software. Keep your Letters. As a reminder Best free firewall zonealarm.com + best free antispyware spybot www.safer-networking.org/ + best free antivirus avg www.grisoft.com/ and go every month to http://update.microsoft.com the letter download |
11-06-2008, 12:10:14
The Register has picked up the story.
http://www.theregister.co.uk/2008/06/11/security_breach_at_belgacom/
Strange to see that in the Belgian press, there is no mention of it all. Very strange.
Richard