Why is Virgin Media asking customers for their passwords?


Recommended Posts

Why is Virgin Media asking customers for their passwords?

Because either it is stupid, or thinks its customers are, or both. Actually, that's slightly (but only slightly) unfair.

The company says that it has indeed been calling customers and asking them to confirm their identities by giving up their passwords and home addresses in order to comply with the Data Protection Act. Which, of course, is the kind of thing a company says when it doesn't have a proper grasp of Data Protection Act compliance.

So what's going on? If you're a Virgin Media customer then you may recently have received a call from someone claiming to be a Virgin Media employee conducting a customer services review on behalf of the company. So far, so believable. Then, this unexpected caller will have asked you to confirm your identity by revealing your password. Or your home address. Or both. How do we know? They called me.

At this point, your identity-theft alarm bell may have sounded at the possibility that you were being phone-phished, socially engineered or otherwise being taken for a berk by someone from Nigeria with 419 similar calls already under their belt. Ringing up and asking for such details is a classic scam.

Except that this isn't a scam. It's real: Virgin Media has actually been doing this. But it must, to comply with the Data Protection Act, remember? What does the Data Protection Act say on compliance? Well, it says a quite lot - around 37,000 long, dull and tedious words - but it doesn't say that companies should call customers unexpectedly and ask for their passwords. That would be stupid.

How stupid? Ask the security-meisters at the Home Office: "Never give personal or account details to anyone who contacts you unexpectedly. Be suspicious, even if they claim to be from your bank or the police."

Admittedly, the Home Office advice doesn't say to be suspicious of callers who say that they're from Virgin Media, so perhaps it's okay to be reckless with your personal data in this instance? Well, actually, no.

When asked to explain the company's policy, Virgin Media said that many major organisations call customers and ask them to confirm their passwords as part of Data Protection Act compliance procedures. This review is, we're told, an ongoing process that could involve any customer at any time. The chap at Virgin Media cited his own bank, NatWest, as an example of another major organisation that does this.

We called NatWest: it doesn't do this. Indeed, NatWest's advice for customers answering unexpected callers is handy: "Be cautious if you're asked for personal information. Remember that they have instigated the call and should already know who you are. NatWest will never ask for your full security number or password." Virgin Media, take note. (Spokesman, check your bank account.)

Our advice is never to give out these details - because it could really be conmen (or women) on the phone trying to get your details.

Source: Guardian

Unbelievable.

Trajic really isn't it.

We try everyday to drum it into people at work about scams / phishes etc, and then these buffoons come along and do this!

Noobs....

I literally hate Virgin Media.. Premium charge for customer support lines even if problem is on their side ???

Bunch of cheaters

Never give out any passwords on such calls. Even if it is legit from any virgin

Thanks for making us aware of this new scam

I don't even ID myself by name when someone phones me... I just say "Hello" and wait for them to ask for who they want. If VM phone me up asking for this kind of info, they can go swim in a lake of piranha fish!

what kills me is the fact that when contacted, Virgin didn't say you know, we are sorry, this is very unsafe and we will change the way we are doing it. They literally just said, it's what we have to do, so tell us or else.........

If your a customer of Orange you're expected to give your password. They are quite possibly the worst ISP I know (apart from Tiscali Dial-up).

They are also guilty of not securely shredding customer documents at their offices, leaving customers personal details in bin bags that anyone could steal.

LOL @ this.

if they call me im going to give them the wrong password and see what they say :p

"whats your password, sir?" ... "...hedgehog" ... "that password is incorrect sir" ... "oh well, nevermind, better luck next time" *puts phone down*

:laugh:

If your a customer of Orange you're expected to give your password. They are quite possibly the worst ISP I know (apart from Tiscali Dial-up).

They are also guilty of not securely shredding customer documents at their offices, leaving customers personal details in bin bags that anyone could steal.

No you don't

It's two random digits from your password with Orange.

I was on the phone to them last week

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I have a Motorola, one of the lower end ones, it works fine. It is possible to get rid of the Gemini app and also to disable googles assistant , but A.i is still apps. I try to avoid all LLM A.I, is i can, I use no Ai duck duck go.
    • Free Software Foundation Europe pushes EU to force Google to allow AI uninstalls on Android by Paul Hill Credit: Pexels Users should be able to fully uninstall AI-based features from Android devices and be able to access interoperability functions, free from Google’s verification requirements, the European Commission has heard as part of an Android interoperability consultation under the Digital Markets Act. These measures were proposed by the Free Software Foundation Europe (FSFE) last week when it submitted its documentation. The FSFE noted that Google had started silently installing AI models without telling users. It noted that the EU’s DMA requires companies like Google to allow users to uninstall pre-loaded software from their devices, but in the case of the AI models Google is installing, they reinstall if you delete them, contravening the DMA. To get Google back under control, the FSFE has told the European Commission that there needs to be improvements within the Android Open Source Project (AOSP). First, it said that users should be able to fully remove pre-loaded AI components from their devices, with companies being prohibited from silently reinstalling or reactivating them. Second, access to Android interoperability features should not be contingent on registration, authorization, or contractual relationships with Google. This pertains to Google’s attempt to force developers to register with Google, even to publish apps to alternative app stores like F-Droid. Discussing its submission, Lucas Lasota, FSFE Legal Programme Manager, said: Google is planning to roll out its Android Developer Certification in September 2026. This will force every Android app developer to register with Google before their software can be installed on certified Android devices, but it should affect those who have removed Google Apps from their device. The program is controversial because it entails the signing of contracts and payment of account fees to Google, as well as the handing over of the identities of developers. It said: The FSFE said that if the Commission’s draft measures remain unchanged, then Google will be allowed to make developers verify their identity. The FSFE believes that asking developers to register is contrary to the text and spirit of the law. In summary, the FSFE has told the Commission that no developer should need a Google account, a Play Store presence, or any agreement with Google to access Android’s interoperability features.
  • Recent Achievements

    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      519
    2. 2
      +Edouard
      188
    3. 3
      PsYcHoKiLLa
      87
    4. 4
      Michael Scrip
      81
    5. 5
      Steven P.
      72
  • Tell a friend

    Love Neowin? Tell a friend!