The Register® — Biting the hand that feeds IT

Orange suspends extranet after attack

Enable disabled

Orange has had to suspend access to its "Enable" system since last Thursday when it became aware that a third party was trying to access the credit checking and connection management system.

In a statement, Orange said someone tried to get in to the system, which is designed for internal and external sales people. Orange wouldn't be drawn on what data, if any, was compromised. The system is designed to manage customers wanting upgrades or coming to the end of their contract, so it seems likely that the attacker was someone who could gain financially from that information.

The most obvious candidate would be a contract reseller, who wanted to call up Orange customers coming to the end of their contracts. Such companies have, in the past, been reduced to calling people at random in the hope of hitting someone near renewal, so they would certainly be interested in details of customers nearing the end of their contracts, including their eligibility and credit rating, as well as name and number.

So, if you're an Orange customer getting suspicious calls offering you a new contract, let us know.

The Reg understands that new usernames and passwords have been issued to legitimate Enable users, though the system isn't fully operational and Orange says it is still investigating. So don't hold your breath. ®

Free Download - The Reg Guide to Extended Validation

Don’t Miss

email symbolStill sending naked email? Get your protection here

Security How-to Buckle your seatbelt, encrypt your bits

Google's Satan phoneT-Mobile G1 Google Android-based smartphone

Review Operating System 1, Hardware 0

Ubuntu teaser Ubuntu 8.10 - All Hail new Network Manager

Review The good kind of UI theft

OpenOffice_logoOpenOffice 3.0 - the only option for masochistic Linux users

Review And linear optimizing Mactards