Six million Sky broadband customers exposed to flaw that could let hackers steal bank info

19 November 2021, 15:55

Around six million Sky broadband customers were exposed to a security hack.
Around six million Sky broadband customers were exposed to a security hack. Picture: Alamy

By Sophie Barnett

Around six million Sky broadband customers were exposed to a security flaw that would have allowed hackers to "control millions of hubs for 18 months", a security company has warned.

Listen to this article

Loading audio...

The flaw has been fixed, but the security researchers said it took Sky nearly 18 months to fix the problem.

The bug was uncovered by the security group Pen Test Partners, who said it affected users who had not changed the router's default admin password.

As this is simple and easy to guess, hackers could easily reconfigure the router and take over a network, just by directing the user to a malicious network.

This could then give hackers access to sensitive information including log-in details for online banking.

According to the researchers, the affected router models were: Sky Hub 3 (ER110), Sky Hub 3.5 (ER115), Booster 3 (EE120), Sky Hub (SR101), Sky Hub (SR203), and the Booster 4 (SE210).

Sky said it had begun working to fix the problem as soon as it was made aware of it and it took the security of its customers "very seriously".

Cyber security expert explains what is behind the twitter hack

Pen Test Partners said there was no evidence the flaw had been exploited, but criticised Sky for the time it took to fix the issue.

It claimed the internet service provider had repeatedly pushed back deadlines it had set to fix the problem.

A spokesman for Sky said: "We take the safety and security of our customers very seriously.

"After being alerted to the risk, we began work on finding a remedy for the problem and we can confirm that a fix has been delivered to all Sky manufactured products."

The initial delay to the time it took for Sky to fix the problem was put down to the coronavirus pandemic, researchers said.

It also said it did not want to disrupt the "vastly increased network loading as working from home became the new norm".

But researchers were concerned by the speed - and time it took - for the company to respond, saying they believed Sky "did not give the patch the priority their customers deserved".

If you have a broadband router mentioned above, the research company has advised you change the passwords on it from the default ones set.

More Latest News

See more More Latest News

Couples who suffer miscarriages could get bereavement leave -with the government backing a proposed change.

Government backs paid bereavement leave for couples who suffer miscarriages

Prime Minister Keir Starmer Hosts Reception At Downing Street To Celebrate International Women's Day

Keir Starmer hails 'remarkable breakthrough' in talks between Ukraine and US as 30-day ceasefire agreed

Newcomen Road

Girl, 13, charged with murder after mother-of-three found dead in house

Billy Joel

Billy Joel postpones tour dates due to 'medical condition' after shock fall on stage

Thousands of patients missed screenings for cancer and other diseases.

Thousands miss NHS screenings for cancer and other diseases in huge admin error

Exclusive
Yuriy Sak

'Time for Trump to play his cards': Ukrainian official 'optimistic' about peace but warns 'Russia can't be trusted'

A US-Ukraine delegation met in Jeddah, Saudi Arabia, as officials agreed the US would resume intelligence sharing and security assistance.

'The ball is in Putin's court': Ukraine accepts 30-day ceasefire offer with White House set to take deal to Russia

Smoke billows from the MV Solong cargo ship in the North Sea, off the Yorkshire coast, Tuesday, March 11, 2025, in England. (Dan Kitwood/Pool Photo via AP)

Cargo vessel's captain arrested for gross negligence manslaughter after North Sea collision

Joanne Penney, 40, has been named as the suspected victim of a shooting in a quiet Welsh neighbourhood.

Four more people arrested after mother shot dead on doorstep in possible case of 'mistaken identity'

Boohoo rebrands as Debenhams

Boohoo rebrands as Debenhams in major overhaul following drop in youth fashion labels' sales

File photo

'Over 100' rail passengers taken hostage in Pakistan after separatist militants hijack train in 'terror attack'

An easyJet pilot has been suspended after his jet flew too close to a mountain

EasyJet flight 'seconds from disaster' after nearly crashing into mountain with 190 passengers on board

Her son said her dogs were "her life." (FILE)

Missing mum found eaten by her two sausage dogs - as son says pets were 'her life'

Tug boats shadow the Solong container ship as it drifts in the Humber Estuary, off the coast of East Yorkshire following a collision with the MV Stena Immaculate oil tanker

Man, 59, arrested for gross negligence manslaughter after North Sea ship collision

Lisa Smith, 43, was with a female friend when she was killed outside the Three Horseshoes pub in Knockholt, Kent.

Body of Valentine's Day shooting suspect formally identified after being pulled from river

US and Ukrainian delegations meet in Saudi Arabia as peace talks begin

‘Sign of hope’ as Zelenskyy’s chief of staff posts ‘handshake emoji’ as Ukraine peace talks under way