The encyclopedia · Software & IT · Technical decision · 2019–2020
Virgin Media left a marketing database open for 10 months — 900,000 exposed
A Virgin Media marketing database was misconfigured and left open for about ten months, exposing roughly 900,000 customers' names, addresses and phone numbers.
Virgin Media · 2020-03
What happened
Virgin Media, one of the UK's largest cable and telecoms providers, kept a marketing database that was incorrectly configured so that it could be accessed without authorisation. The misconfiguration was not caught for about ten months. In March 2020 the company disclosed that roughly 900,000 people had been affected, including fixed-line customers representing about 15% of that customer base.
The exposed data was contact information: names, home and email addresses and phone numbers. Virgin Media said the database held no passwords and no financial details such as credit card or bank account numbers. The company said it became aware of the issue, shut down access to the database, and kept the Information Commissioner's Office updated.
The case is small next to the mega-breaches, but its mechanism is the common one: the database was not hacked so much as left open. A configuration mistake sat unmonitored for the better part of a year, and the gap between 'set up' and 'checked' became the exposure of nearly a million customers' personal details.
Why it happened
- A marketing database was incorrectly configured so it could be reached without authorisation.
- The misconfiguration went undetected for about ten months, so the window of exposure was long before anyone looked.
- The database held the contact details of roughly 900,000 people — names, home and email addresses and phone numbers.
- No monitoring or access review caught the open database; the failure was an absence of checking, not a sophisticated attack.
The lesson
Customer data needs an owner who checks it. Virgin Media's marketing database sat misconfigured for ten months before anyone noticed — the breach was the gap between 'configured' and 'monitored'.
Aftermath
Virgin Media shut down access to the database, contacted affected customers and kept the UK Information Commissioner's Office updated. Because no financial data or passwords were exposed, the immediate harm to customers was limited, but the incident is cited as a textbook example of how data breaches usually happen: not through a clever intrusion, but through a misconfigured system that nobody was watching.
Sources
- Virgin Media — 'Virgin Media's data incident', 5 March 2020 (marketing database incorrectly configured; ~900,000 people; contact data only; ICO kept updated)
- BBC News — 'Virgin Media data breach affects 900,000 people', March 2020
spotted an error? The club wants to know.
More like this
Energis was a £10B UK telecom — it collapsed in 2002 when the dot-com bubble burst
A software change took Verizon's 5G core down 10 hrs — 2M lost calling, texting and 911
A cyberattack froze Jaguar Land Rover's whole manufacturing estate for about five weeks
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.