Just saw this, so thought it's worth pointing out who are with Mercury.
https://www.reddit.com/r/newzealand/comments/1nb8osd/mercury_energy_customers_heads_up_your_data_is/
Just saw this, so thought it's worth pointing out who are with Mercury.
https://www.reddit.com/r/newzealand/comments/1nb8osd/mercury_energy_customers_heads_up_your_data_is/
----
Creator of whatsthesalary.com and whatstheincometax.com
|
|
|
Can we have a security sub-forum?
An update to the original reddit post. https://www.reddit.com/r/newzealand/comments/1nb8osd/mercury_energy_customers_heads_up_your_data_is/

So looks like someone from Mercury is looking at it.
@MadEngineer:
Can we have a security sub-forum?
Do we need one? How many discussions like this happen?
Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies
Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.
freitasm:
@MadEngineer:
Can we have a security sub-forum?
Do we need one? How many discussions like this happen?
hoping not a lot…
----
Creator of whatsthesalary.com and whatstheincometax.com
Not many that I've seen but it'd be nice to have more discussions on it
Cybersecurity week next month. I have lined up some freebies to giveaway.
Who knows?
Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies
Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.
Anyone with Mercury able to request access logs to their account? That will answer two questions - the obvious but also if they’re even logging API access at all.
Parts of their App is offline for maintenance, namely the Rewards section.
Here is a crazy notion, lets give peace a chance.
Just got the email:
Potential rewards data breach
On Monday, we became aware of an issue with rewards in My Account, accessed from the Mercury app and website. While we investigated, we temporarily switched off rewards.
We found that limited information stored under your rewards profile may have been accessible to other people. This information includes your account number, name, and property address. Following our investigation, we believe it’s unlikely your rewards profile has been accessed and misused. It would have required a high level of technical expertise to find this information. We’re sincerely sorry this happened.
We take our responsibilities with customer information seriously. Additional security measures have been established to prevent access to this information. Rewards is now available again.
What does this mean for you?
Scammers are becoming increasingly sophisticated. If you receive a suspicious email, call, or text, please immediately report it to Mercury. You can also report suspicious activity to the National Cyber Security Centre (NCSC) or Netsafe by searching for these names online.
Thanks,
The team at Mercury
Interesting to hear that they think changing API endpoint/payload with the same authentication token is "highly technical expertise". Maybe it is and I'm living in a bubble.
It would have required a high level of technical expertise to find this information.
----
Creator of whatsthesalary.com and whatstheincometax.com
jamesrt:
It would have required a high level of technical expertise to find this information.
Umm... OK, sure, BUT what that person who does find the info does with it is the problem.
They don't have to be technical to blackmail/ransom people.
That is a really **** comment to have in that email.
XPD / Gavin
turtleattacks:
Interesting to hear that they think changing API endpoint/payload with the same authentication token is "highly technical expertise". Maybe it is and I'm living in a bubble.
It would have required a high level of technical expertise to find this information.
To marketing people inspect element is elite level hacking skills used to steal an image from a website. API is just mindblowing crazy talk.
richms:
To marketing people inspect element is elite level hacking skills used to steal an image from a website. API is just mindblowing crazy talk.
To marketing people, "View source" or "developer tools" are totally North Korean leet grade hacking 😃
|
|
|