Menu
Browse

Cyber Incident Victim: Aerial Direct

Date:

Feb 2020

Location:

United Kingdom

Summary

Aerial Direct, a major UK telecommunications partner for O2, experienced unauthorized third-party access to an external backup database containing personal information of current and former business customers. The compromised data included names, dates of birth, business addresses, email addresses, phone numbers, and product details, though no financial information or passwords were accessed. The company immediately disabled system access upon discovery, initiated an investigation with external experts, and notified the UK Information Commissioner's Office. With over 130,000 customers affected, the firm established a dedicated support resource advising vigilance and password updates while emphasizing monitoring of financial accounts for suspicious activity.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around February 26, 2020, an unauthorized third party accessed customer data stored in an external backup database managed by Aerial Direct, a major UK business communications partner of mobile network O2. The breach involved personal information from both current and former subscribers spanning the previous six years. Compromised data included names, dates of birth, business addresses, email addresses, phone numbers, and product information, though the company confirmed no passwords or financial details were exfiltrated. Aerial Direct detected the incident promptly and terminated system access to contain the intrusion. The organization initiated a comprehensive investigation with external cybersecurity experts to determine the attack's scope and methodology. It formally reported the breach to the UK Information Commissioner's Office (ICO) in compliance with regulatory obligations.

Cyber Incident Image

Aerial Direct, headquartered in Fareham, England, served over 130,000 business customers as O2's largest direct UK partner at the time, providing mobile, fixed-line, broadband, and conferencing services. The company established a dedicated support webpage advising affected customers to change account passwords and monitor financial statements for suspicious activity, recommending direct contact with banks if irregularities were detected. Its 2018 financial filings showed annual revenues of £21.6 million with £6.9 million in EBITDA, indicating its substantial market presence. The breach notification emphasized ongoing efforts to analyze the attack vector while maintaining operational continuity for client services. No additional technical details regarding the backup system's architecture or the attackers' entry method were disclosed publicly.

Sources
Sources available to members
1 source