Sky Customers Told To Change Passwords – Report

There is speculation of a possible a security incident at Sky, after it emailed account holders asking them to change their passwords immediately.

The Sky email said the password change was part of a “security measure”, Techradar reported, and the email alert apparently contains a link for users to choose a new password.

But with no public confirmation from Sky, it should be remembered that there could have been no security issue that has promoted the password change request. Indeed, Sky reportedly said it has not been breached.

Data incident?

“At Sky we take the security of your data and information extremely seriously. To help keep your account safe we have reset the password for your Sky account,” the email reportedly reads.

A number of Sky customers took to Twitter to ask Sky if the emails were genuine, or part of a phishing scam.

The firm’s official account apparently replied they were genuine, Techradar reported.

“To help keep customer’s accounts safe we occasionally reset the password for Sky accounts. Customers can reset their password online at Sky.com,” a Sky spokesperson reportedly said, but said the company has not been breached.

However the account also reportedly told some customers that the reset was linked to “part of the incident that happened last week”, possibly referencing a recent attack.

Sky has reportedly already locked the accounts of all affected users, who will need to contact the company to get control back.

The lack of public confirmation from the company has not helped matters, and it be noted that Sky’s password advisory could be down to data breaches at other firms, with hackers trying to access Sky accounts using data stolen in other breaches.

Precautionary measures

“The latest news regarding password resets occurring for email accounts with sky.com, as so-called “precautionary measures” that have been taken, indicates that the incident is ongoing and possibly the root cause is still unknown,” noted Joseph Carson, Chief Security Scientist & Advisory CISO at Thycotic.

“If indeed this was a credential stuffing cyberattack, then there would be an indicator of a high number of failed logon attempts, hopefully resulting from some users following best practices by not using the same password across multiple accounts,” Carson added. “This is what credential stuffing is trying to abuse using an automated process.”

“Credential stuffing normally happens when using credentials from other data breaches and attempting to use those same passwords to unlock accounts from other online services, such as email or bank accounts,” he said. “Credential stuffing can raise alarms quite quickly if monitoring is in place.”

“Sky need to be following incident response best practices and treating this incident as serious because, in many cyber incidents, you tend to uncover more serious data breaches when you start looking harder,” he added. “Sky customers should really start using password managers and two factor authentications to ensure that a password is not the only security protecting sensitive data.”

Do you know all about security? Try our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Google Delays Removal Of Third-Party Cookies, Again

For third time Google delays phase-out of third-party Chrome cookies after pushback from industry and…

8 mins ago

Tesla Posts Biggest Revenue Drop Since 2012

Elon Musk firm touts cheaper EV models, as profits slump over 50 percent in the…

57 mins ago

Apple iPhone Q1 Sales In China Fall 19 Percent, Says Counterpoint

Bad news for Tim Cook, as Counterpoint records 19 percent fall in iPhone sales in…

5 hours ago

President Biden Signs TikTok Ban Or Divest Bill Into Law

TikTok pledges to challenge 'unconstitutional' US ban in the courts, after President Joe Biden signs…

6 hours ago

UK CMA Seeks Feedback On Microsoft, Amazon AI Partnerships

British regulator invites feedback on major partnerships Microsoft and Amazon have struck with smaller AI…

22 hours ago

Google Fires More Staff Over Israel Protest

Another 20 staff have been fired by Google over Israel protest and their “completely unacceptable…

23 hours ago