UK telecommunications firm TalkTalk is investigating a third-party provider knowledge breach after a menace actor started promoting alleged buyer knowledge on a hacking discussion board.
“As a part of our common safety monitoring, given our ongoing give attention to defending prospects’ private knowledge, we had been made conscious of surprising entry to, and misuse of, one in every of our third-party provider’s programs, nevertheless, no billing or monetary info was saved on this method,” TalkTalk advised BleepingComputer.
“Our Safety Incident Response group are persevering with to work with the provider concerning this matter and protecting containment steps had been taken instantly.”
“Our investigations are ongoing, nevertheless we are able to verify that the variety of potential prospects referred to in sure on-line posts is wholly inaccurate and really considerably overstated.”
This assertion comes after somebody named “b0nd” started promoting what they declare is TalkTalk buyer knowledge on a hacking discussion board that was allegedly stolen in a January 2025 knowledge breach.
“Because the title says right now we are going to listing on the market a big knowledge breach involving TalkTalk. This breach occurred January 2025 and impacts 18,839,551 present and former prospects.” reads the submit to a hacking discussion board.

Supply: BleepingComputer
The menace actor additionally shared a pattern of the information, which incorporates the subscriber’s title, electronic mail, last-used IP handle, enterprise telephone quantity, and residential telephone quantity.
Whereas the discussion board submit says the stolen knowledge comprises details about virtually 18.9 million present and former TalkTalk prospects, the corporate doesn’t have practically that variety of subscribers, placing the authenticity of the breach unsure.
Moreover, the screenshots shared by the menace actor point out that the information was presumably stolen from the Ascendon SaaS platform moderately than straight from TalkTalk.
CSG Ascendon is a subscription administration platform that TalkTalk has traditionally used as a part of its operations.
In 2015, TalkTalk suffered a knowledge breach the place hackers accessed the private particulars of over 150,000 prospects. The incident led to a £400,000 tremendous by the UK Info Commissioner’s Workplace.
BleepingComputer contacted the CSG to substantiate in the event that they suffered a breach however has not acquired a reply.