Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


turtleattacks

1008 posts

Uber Geek
+1 received by user: 305

Trusted

#322645 8-Sep-2025 12:06
Send private message

Just saw this, so thought it's worth pointing out who are with Mercury. 

 

https://www.reddit.com/r/newzealand/comments/1nb8osd/mercury_energy_customers_heads_up_your_data_is/

 

 





View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
MaxineN
Max
2049 posts

Uber Geek
+1 received by user: 1662

ID Verified
Trusted
Subscriber

  #3412390 8-Sep-2025 12:14
Send private message

@taneb1

 

 

 

Whilst I'm skeptical, I'm glad there's been no PoC posted.





Ramblings from a mysterious lady who's into tech. Warning I may often create zingers.




MadEngineer
4591 posts

Uber Geek
+1 received by user: 2570

Trusted

  #3412614 8-Sep-2025 15:27
Send private message

Can we have a security sub-forum?





You're not on Atlantis anymore, Duncan Idaho.

djtOtago
1181 posts

Uber Geek
+1 received by user: 605


  #3412630 8-Sep-2025 15:47
Send private message

An update to the original reddit post. https://www.reddit.com/r/newzealand/comments/1nb8osd/mercury_energy_customers_heads_up_your_data_is/

 


 

So looks like someone from Mercury is looking at it.




xpd

xpd
Geek of Coastguard
14115 posts

Uber Geek
+1 received by user: 4574

Retired Mod
ID Verified
Trusted
Lifetime subscriber

  #3412637 8-Sep-2025 16:22
Send private message

Was only after he went public with it tho..... and thats the issue with a lot of companies when vulnerabilities etc are found, they ignore it until the public are made aware.

 

 

 





XPD / Gavin

 

LinkTree

 

 

 


freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41030

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3412661 8-Sep-2025 18:51
Send private message

@MadEngineer:

 

Can we have a security sub-forum?

 

 

Do we need one? How many discussions like this happen?





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


turtleattacks

1008 posts

Uber Geek
+1 received by user: 305

Trusted

  #3412662 8-Sep-2025 18:59
Send private message

freitasm:

 

@MadEngineer:

 

Can we have a security sub-forum?

 

 

Do we need one? How many discussions like this happen?

 

 

hoping not a lot…

 

 





 
 
 
 

Shop now for Lenovo laptops and other devices (affiliate link).
MadEngineer
4591 posts

Uber Geek
+1 received by user: 2570

Trusted

  #3412680 8-Sep-2025 21:26
Send private message

Not many that I've seen but it'd be nice to have more discussions on it





You're not on Atlantis anymore, Duncan Idaho.

freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41030

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3412684 8-Sep-2025 21:34
Send private message

Cybersecurity week next month. I have lined up some freebies to giveaway.

 

Who knows?





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


MadEngineer
4591 posts

Uber Geek
+1 received by user: 2570

Trusted

  #3412807 9-Sep-2025 08:55
Send private message

Anyone with Mercury able to request access logs to their account?  That will answer two questions - the obvious but also if they’re even logging API access at all.





You're not on Atlantis anymore, Duncan Idaho.

MikeB4
MikeB4
18775 posts

Uber Geek
+1 received by user: 12765

ID Verified
Trusted
Subscriber

  #3412809 9-Sep-2025 09:08
Send private message

Parts of their App is offline for maintenance, namely the Rewards section.





Here is a crazy notion, lets give peace a chance.


jamesrt
1663 posts

Uber Geek
+1 received by user: 941

ID Verified
Trusted
Lifetime subscriber

  #3414054 12-Sep-2025 10:38
Send private message

Just got the email:

 

Potential rewards data breach

 

On Monday, we became aware of an issue with rewards in My Account, accessed from the Mercury app and website. While we investigated, we temporarily switched off rewards.

We found that limited information stored under your rewards profile may have been accessible to other people. This information includes your account number, name, and property address. Following our investigation, we believe it’s unlikely your rewards profile has been accessed and misused. It would have required a high level of technical expertise to find this information. We’re sincerely sorry this happened.

We take our responsibilities with customer information seriously. Additional security measures have been established to prevent access to this information. Rewards is now available again. 

What does this mean for you?

 

  • There is nothing you need to do. We believe it’s unlikely your rewards profile has been accessed, and we continue to strengthen our rewards security. It’s important to know that no passwords, payment information, email addresses, or phone numbers are stored under your rewards profile.
  • We’ve notified the Privacy Commissioner. You have the right to make a complaint to the Privacy Commissioner.  
  • You can continue to enjoy rewards, like you always have. 

Scammers are becoming increasingly sophisticated. If you receive a suspicious email, call, or text, please immediately report it to Mercury. You can also report suspicious activity to the National Cyber Security Centre (NCSC) or Netsafe by searching for these names online.

Thanks,

The team at Mercury

 

 


HP

 
 
 
 

Shop now for HP laptops and other devices (affiliate link).
turtleattacks

1008 posts

Uber Geek
+1 received by user: 305

Trusted

  #3414057 12-Sep-2025 10:41
Send private message

Interesting to hear that they think changing API endpoint/payload with the same authentication token is "highly technical expertise". Maybe it is and I'm living in a bubble. 

 

It would have required a high level of technical expertise to find this information.





xpd

xpd
Geek of Coastguard
14115 posts

Uber Geek
+1 received by user: 4574

Retired Mod
ID Verified
Trusted
Lifetime subscriber

  #3414059 12-Sep-2025 10:42
Send private message

jamesrt:

 

It would have required a high level of technical expertise to find this information. 

 

 

Umm... OK, sure, BUT what that person who does find the info does with it is the problem. 

 

They don't have to be technical to blackmail/ransom people.

 

That is a really **** comment to have in that email.

 

 

 





XPD / Gavin

 

LinkTree

 

 

 


richms
29098 posts

Uber Geek
+1 received by user: 10207

Trusted
Lifetime subscriber

  #3414068 12-Sep-2025 10:55
Send private message

turtleattacks:

 

Interesting to hear that they think changing API endpoint/payload with the same authentication token is "highly technical expertise". Maybe it is and I'm living in a bubble. 

 

It would have required a high level of technical expertise to find this information.

 

 

To marketing people inspect element is elite level hacking skills used to steal an image from a website. API is just mindblowing crazy talk.





Richard rich.ms

wellygary
8810 posts

Uber Geek
+1 received by user: 5287


  #3414107 12-Sep-2025 12:26
Send private message

richms:

 

To marketing people inspect element is elite level hacking skills used to steal an image from a website. API is just mindblowing crazy talk.

 

 

To marketing people, "View source" or "developer tools" are totally North Korean leet grade hacking 😃


 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.