dslreports logo
 story category
Time Warner Cable, Bright House E-mail Passwords Stolen

Time Warner Cable and Bright House Networks are reaching out to hundreds of thousands of customers to inform them that their e-mail passwords may have been stolen. In an e-mail to users, Time Warner Cable states that the FBI contacted the company to inform it that "some of our customers' email addresses, including account passwords, may have been compromised." Time Warner Cable says it's not sure how the breach happened, but that users should (obviously) change their passwords.

Click for full size
"Our understanding is that the compromise had nothing to do with TWC's systems or processes," the company says. "TWC has found no evidence of a breach in its systems that operate and secure email accounts for our customers."

Bright House Networks customers in our forums say they've been getting the warning e-mail too (Bright House leans heavily on Time Warner Cable for numerous business functions, including negotiating programming deals).

"As part of an ongoing FBI investigation, Bright House Networks recently learned that some of our customer's email addresses and account passwords may have been compromised," states the warning.

"It is our understanding that the emails and passwords were likely previously stolen either through malware downloaded during phishing attacks or indirectly through other third-party data breaches," a Bright House representative states in our forums.

It's likely that the account passwords were noticed by the FBI during an investigation or popped up on the dark net, where such data is routinely sold after being obtained in phishing, malware, or other attacks. Comcast recently found the data of 590,000 users pop up on the dark net for sale.

Most recommended from 25 comments


Kearnstd
Space Elf
Premium Member
join:2002-01-22
Mullica Hill, NJ

6 recommendations

Kearnstd

Premium Member

Time for a new Fee!

Its time for them to add a new Fee I bet...

They will call it...

"User Security Fee" And market it as covering the costs of keeping customer information secure and covering the costs of reacting to potential leaks, Even though they make enough money already and keeping data secure should have been part of company policy.
alexintexas
join:2003-01-11
San Antonio, TX

6 recommendations

alexintexas

Member

Whats new

how many TWC customers actually use TWC mail servers.

I know i dont

battleop
join:2005-09-28
00000

5 recommendations

battleop

Member

This is never going to end.

This stuff is built, managed, and maintained by humans so a perfect system is not possible. No matter what is done there will always be exploits that all this to happen.

spagafus
@usps.gov

5 recommendations

spagafus

Anon

story category Time Warner Cable, Bright House E-mail Passwords Stolen

Good or bad many people use the TWC/RR email services. According to some articles the majority of the accounts affected by this breach were rr.com. It makes sense because the rr.com email servers do not support SSL/TLS and use plain text passwords. There are many users with email clients and smartphones who are using POP3 settings without encryption. Even if TWC/RR added SSL recently, and I don't think they have, few people would have gone back to change their email setup.
xthepeoplesx
join:2013-10-21

3 recommendations

xthepeoplesx

Member

In other news...

In other news, the two grandparents still using time warner cable email addresses have paused Matlock to check their spam filters for their kids vacation photos.

grnadi
@wideopenwest.com

2 recommendations

grnadi

Anon

source of the breach

If one is to be charitable and take TWC at its word, what other services have significant customer overlap with TWC and BHN? Or is this just another example of the dangers of using one passcode for everything?
scanman1
join:2010-11-25

2 recommendations

scanman1

Member

BHN was warned again here and I gave a TWC server solution in June 2015!

I just re-posted the NON-BHN POP3 TWC settings again that I had to figure out on my own on Jan 4th for someone here just a few days ago:

»Email set up

I have been very vocally complaining here for a long time that BHN would not support SSL/TLS for pop3 email and Gary ignored my posts as they are not running the servers. There has been a lack of coordination between TWC and BHN to show users how to set up secure email. It's no wonder the POP3 accounts have been sniffed.

Lets go down memory road in this issue on this forum:

I posted an unauthorized HOW TO thread back in June of 2015 to use the unpublished secure TWC servers directly for all xxxx.rr.com accounts in this thread when I discovered through trial and error that TWC servers could be used by BHN customers directly and securely and it was all but ignored and people blindly continued to use open passwords to be sniffed by all that were in the path between any customers device and BHN email servers:

»[Internet] WORKING unpublished BH SECURE ENCRYPTED Email server settings!

This was legitimately asked in this forum all the way back in 2012 and was was given the complete cold shoulder by Gary with this reply:

Re: [Internet] Why doesn't Brighthouse offer secure/ssl email server?

Gary:
The simple answer is extremely low risk of such a thing happening and the plethora of services available to consumers who for whatever reason feel the need for such a thing.

»[Internet] Why doesn't brighthouse offer secure/ssl email server

I personally begged here myself and reminded BHN that this was a gross and utter security violation again in this thread back in April of 2014:

»More "exciting" POP E-mail Upgrades?

I reminded Gary again on March 2014:
»Re: [Internet] Best Routers for Bridged Networks

Port 110 and open transmission of email login and passwords has finally OPENLY bit BHN in the ass. It's not like they were not warned!!!