
Virgin Media O2 mobile users' locations exposed for two years in security flaw
The locations of millions of Virgin Media O2 mobile customers were exposed for up to two years until a network security flaw was corrected, it has emerged.
Before the fix was implemented on 18 May, anyone with a Virgin Media O2 sim card could use their phone to obtain sensitive information about the network's other customers using a 4G-enabled device, including their location to the nearest mobile mast.
The flaw has now been patched and reported to the UK's communications and data protection regulators. Virgin Media O2 said there was no evidence that its network security systems had been externally breached.
The locations of customers could be tracked most precisely in urban areas, where mobile masts cover areas as small as 100 square metres.
Dan Williams, an IT specialist who discovered the defect, wrote that he was 'extremely disappointed' not to receive a response when he flagged the issue, which was resolved only after he blogged about it two months later, on 17 May. He said there had been no explanation for the delay.
He wrote: 'I don't want to be the enemy, I simply want to feel comfortable using my phone.'
Williams noticed Virgin Media O2's failure to configure its 4G calling software correctly when he was looking at messaging between his device and the network to work out call quality between himself and another O2 customer.
'I noticed that the responses from the network were extremely long, and upon inspection noticed that extra information from the recipient of the call was sent to the call initiator,' he told the Guardian.
This included normally private information, such as the cell ID, which is the current cell tower a caller is connected to; information about sim card, which could be used for a cyber-attack; and the phone model, which can be used to work out how to access it.
He believed that it was 'possible this was used in the wild and not reported against' though there was no way to quantify that. If it had been that would be 'quite a large problem', as 'there are situations where this data is extremely, extremely sensitive', for example domestic abuse survivors or government workers, he added.
'I came across it by accident. Someone purposefully trying to find these kinds of vulnerabilities would have probably come across it,' he said. 'There are white papers detailing this exact scenario and warning networks against doing this.'
The FT, which first reported Williams's findings, said he had tested the problem with another O2 customer, successfully tracking them to Copenhagen, Denmark.
Disabling the 4G calling feature on devices would have prevented them from being tracked, though this is not possible on some handsets, such as iPhones. The issue may have also affected some customers of Giffgaff and Tesco Mobile, which use Virgin Media O2's network.
Sign up to Business Today
Get set for the working day – we'll point you to all the business news and analysis you need every morning
after newsletter promotion
Alan Woodward, cybersecurity professor at Surrey University, said location data 'could be valuable for scams such as social engineering, or even blackmail' and for phishing attempts referencing a recent location, though they would need other information about the person for this to work.
He said this was unlikely to happen for normal people who were not criminal targets, but nevertheless fixing the vulnerability should have been a 'matter of urgency'.
A Virgin Media O2 spokesperson said: 'Our engineering teams had been working on and testing a fix for this configuration issue over a number of weeks, and we can confirm this fix was fully implemented on 18 May.
'Our customers do not need to take any action, and we have no evidence of this issue being exploited beyond the two illustrative examples given by a network engineer in his blog which we reported to the ICO [Information Commissioner's Office] and Ofcom. There has been no external compromise of our network security at any time.'
An Ofcom spokesperson said it was 'aware that O2 has experienced a network security issue', and is in contact with the provider to establish the scale and cause of the problem.
An ICO spokesperson said that after assessing the information provided by Telefonica and remedial steps taken, 'we will not be taking further action at this stage'.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


BBC News
26 minutes ago
- BBC News
Is 'bad attitude' useful? Fans on Cunha signing
We asked for your views on Matheus Cunha signing for Manchester are some of your comments:Nick: I'm happy with this. We're creating, but not scoring, so getting someone in who has experience scoring in the Premier League can only be a good I think it is a fantastic signing in this struggling Manchester United era. I see hope because he can play in so many positions in Ruben Amorim's 3-4-3/3-4-2-1 and United need goals, that's all they Cunha has the skills but does he have the temperament for the most 'under the microscope' and 'under pressure' club currently in the world? I hope so but so much needs to change around him to get the best from him. Let's hope Amorim's plan gets the support from the boardroom. I'm still holding my At last; the right player, at the right price and at the right age. What could go wrong?Karl: Definitely a step in the right direction. His stats say he has everything we've been missing - awareness, speed, balance, a finishing edge and above all, confidence. Can't wait to see how he works alongside the likes of Amad, Fernandes and Yes, he's renowned for his 'bad attitude' but that's just because he wants to win, which is an attitude sadly lacking in quite a few of our current squad. I seem to recall a certain Mr Cantona was slated for his attitude when we signed him!


FF News
28 minutes ago
- FF News
Monzo Reports 8x Surge in Profits to £113.9 Million on the Back of Record Growth
Monzo, the UK's leading digital bank with more than 12 million customers, has today shared its financial results for the year ending March 31 2025. Monzo has again delivered record growth and sustainable profitability as it continues to see momentum accelerate. Recently crowned Best British Bank, the company attracted 2.4 million new customers in its last financial year and saw engagement and weekly active rates continue to increase further – with 67% of customer growth coming from word-of-mouth referrals. Revenues increased significantly across all areas – including lending, transactions and subscriptions – propelling Monzo's adjusted profit before tax to £113.9m, up from £13.9m. Customer deposits grew 48% to £16.6bn, with the number of weekly active users increasing 28% as Monzo added a record number of new products and features to help customers manage more of their financial lives. Average Revenues per User grew 16% for business customers and 15% for personal customers, underscoring the deeper relationships Monzo is building with its customer base. The financial year saw Monzo scale and invest with discipline as it made further strides on its ambition to become the one app customers turn to to manage their entire financial lives. The company welcomed a new generation of customers through its hugely successful Under 16s product, which saw a 180,000-strong waitlist in its first week alone, and launched Monzo Pension. Its new subscription plans – Monzo Perks, Extra and Max – were a huge success with almost 900,000 personal customers now paying for extra benefits. Monzo Business accelerated at pace on the back of the launch of Monzo Team, a product that serves more complex needs for larger small businesses. Together, these new products contributed to an increase in subscriptions income of 50% to £75.2m. The total number of business customers grew by 49% to reach 625,000, with Monzo Business making up 12% of total revenue. The company brought more game-changing savings features to the palms of customers' hands – with the 1p Saving Challenge, launched in January, attracting more than 1 million customers who have collectively saved around £30m so far. With 2.3 million people using Monzo's Instant Access Savings product, the company paid more than £250 million in interest to customers in the last financial year. Leveraging its in-house tech stack, Monzo continues to develop industry-first security tools for its customers. FY2025 saw the business launch a trio of unique security features including Known Locations and Trusted Contacts, to help prevent customers from falling victim to fraud. In addition, and led by its expert financial crime teams, Monzo's real-time fraud detection and prevention system is using AI to trigger a range of interventions. In FY2025 Monzo prevented 2.9 times the value of unauthorised fraud compared to the previous year. Engineers also pioneered Monzo Stand-In, a separate back-up banking infrastructure that ensures customers can continue to use important services in the rare event of an outage. In an industry where platform outages continue to cause mass disruption and worry for customers, Monzo invested in a solution for its customers, giving them the service they deserve from their bank. Monzo maintains a market-leading average Net Promoter Score of +70 – in an industry where the average is around 30 in the UK. The most recent YouGov Brand Index showed that Monzo is out-pacing the rest of the banking industry on metrics including consideration, recommendation, and satisfaction. Two months into the new financial year, Monzo continues to bring new products to customers with the launch of Contents Insurance and Undo Payments – another industry-first tool to help customers have more control over their money. Growth has continued to accelerate, with the company attracting more than 300,000 new customers in April alone – making it its biggest acquisition month yet. In May, Monzo was named Best British Bank, Best Banking App and Best Children's Financial Provider at the British Bank Awards – which is voted for by customers. Looking ahead, Monzo is accelerating its international ambitions. The business is continuing to build out its product offering in the US, and has established its European base with an office and a growing leadership team in Ireland. In the UK, product expansion continues at pace, with additional features across personal and business accounts soon to be announced. TS Anil, Group CEO of Monzo, said,:'Another year of raising the bar and driving scale, growth and profitability! 2.4 million customers chose Monzo, we launched more products than ever, increased customer engagement – and saw record growth for Monzo Business. By bringing the best of technology and banking together and remaining customer-obsessed, we're seeing accelerating growth and momentum and unprecedented customer love – with Monzo recently named Best British Bank. And the best part? We're still just getting started. '


Reuters
28 minutes ago
- Reuters
UK's Rosebank Industries in talks to buy US-based ECI for less than $1.9 billion
June 2 (Reuters) - British investment firm Rosebank Industries (ROSE.L), opens new tab said on Monday it is in talks to buy U.S.-based Electrical Components International, which makes wire harnesses, for less than $1.9 billion.