Back to the archive

The encyclopedia · Software & IT · Technical decision · 2019–2020

Virgin Media left a marketing database open for 10 months — 900,000 exposed

A Virgin Media marketing database was misconfigured and left open for about ten months, exposing roughly 900,000 customers' names, addresses and phone numbers.

Virgin Media · 2020-03

What happened

Virgin Media, one of the UK's largest cable and telecoms providers, kept a marketing database that was incorrectly configured so that it could be accessed without authorisation. The misconfiguration was not caught for about ten months. In March 2020 the company disclosed that roughly 900,000 people had been affected, including fixed-line customers representing about 15% of that customer base.

The exposed data was contact information: names, home and email addresses and phone numbers. Virgin Media said the database held no passwords and no financial details such as credit card or bank account numbers. The company said it became aware of the issue, shut down access to the database, and kept the Information Commissioner's Office updated.

The case is small next to the mega-breaches, but its mechanism is the common one: the database was not hacked so much as left open. A configuration mistake sat unmonitored for the better part of a year, and the gap between 'set up' and 'checked' became the exposure of nearly a million customers' personal details.

Why it happened

  • A marketing database was incorrectly configured so it could be reached without authorisation.
  • The misconfiguration went undetected for about ten months, so the window of exposure was long before anyone looked.
  • The database held the contact details of roughly 900,000 people — names, home and email addresses and phone numbers.
  • No monitoring or access review caught the open database; the failure was an absence of checking, not a sophisticated attack.
What it cost900,000 customers' contact data exposedembarrassing

The lesson

Customer data needs an owner who checks it. Virgin Media's marketing database sat misconfigured for ten months before anyone noticed — the breach was the gap between 'configured' and 'monitored'.

Aftermath

Virgin Media shut down access to the database, contacted affected customers and kept the UK Information Commissioner's Office updated. Because no financial data or passwords were exposed, the immediate harm to customers was limited, but the incident is cited as a textbook example of how data breaches usually happen: not through a clever intrusion, but through a misconfigured system that nobody was watching.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →