Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Wonga Data Breach – Be warned: data breaches provide a distribution hub for malware for years to come

by The Gurus
April 13, 2017
in Editor's News
Share on FacebookShare on Twitter

Payday lender Wonga announced this week it had suffered a data breach which could affect 250,000 of its customers in the UK and a further 25,000 in Poland.
Information reported to have been stolen includes names, addresses, phone numbers, email addresses and bank account details.
This has left those affected with a host of potential problems. With valuable private data stolen, victims are now exposed to “additional attacks, either by the initial attackers or other criminals to whom they sell the compromised data”, claims Brian Laing, VP Product Development at Lastline. He adds, “they [attackers] merge data from multiple sources, building dossiers on potential victims, including spear phishing targets inside corporations. Every breach is a reminder of the importance of strong authentication measures in both personal and professional devices, networks, and web applications.”
“The blurring of personal and professional use of enterprise assets such as laptops underscores the criticality of protecting organizations from the network core to the outer edges against advanced persistent threats and evasive malware that could be introduced because of an infected personal device targeted as a result of a prior data breach, such as the Wonga breach”, and he warns that data breaches provide a distribution hub for malware for years to come.
Wonga have said they are “urgently investigating illegal and unauthorised access” to the personal data but have not disclosed where the breach had taken place.
A help page has been sent up by the payday lender for affected customers which advises the following:

  • Alert their bank and ask them to look out for any suspicious activity. Wonga will also be informing financial institutions about the breach
  • Watch out for scammers or unusual online activity. Customers are told to be cautious about cold calls and emails asking for personal information
  • Contact the Wonga helpline on 0207 138 8330 for further questions

The advice given by the FAQ appears to be contradictory, however, as Wonga is offering assurances by saying “we believe that your account is secure and you do not need to take any action” but also says “if you are concerned you should change your account password.
Security researcher, Lee Munson at Comparitech has picked up on Wonga’s apparent confusion by saying “the company’s own FAQ says it believes that all customer accounts are secure and that no action is required while, at the same time, suggesting that personal and banking information may have been stolen. For a quarter of a million Wonga customers paying upwards of 1,500% interest on their short-term loans, the APR may be the least of their concerns right now. Given the confusion, all Wonga customers should take some basic post-hack precautions, such as changing passwords, checking credit reports and being on the lookout for suspicious emails that appear to come from the company. For Wonga, this event should serve as a stark reminder that incident response is a vitally important part of dealing with a breach and several lessons need to be learned from this incident.”
Gavin Millard, EMEA Technical Director at Tenable Network Security agrees that those affected are now targets from attackers and must take severe precaution. “A favourite trick by scam artists is to use the data swiped to build up trust and credibility with a target to then request further information they don’t have, so customer should be extra careful dealing with unsolicited calls irrelevant of who they claim to be. Whilst Wonga’s post breach FAQ states they “don’t believe your Wonga account password was compromised”, I would strongly advise changing this password wherever it has been reused.

Tags: BreachCyberdatasecurityTechnology
ShareTweet
Previous Post

Pressures Security Professionals Face Have Become More Personal

Next Post

New research reveals that 30 percent of malware attacks are zero day exploits

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol