So Camelot, the National Lottery operator said it became aware of “suspicious activity” on a number of players’ online National Lottery accounts on Monday. Camelot said it believes that “around 26,500 players’ accounts were accessed”, but fewer than 50 accounts have had activity take place since the activity had been activated. Unlike Talk Talk, Tesco and Yahoo, this incident in fact was not a “hack” It has been clear that it’s own internal, core systems and databases were not compromised and it acted swiftly and decisively when the suspicious activity of mass personal data editing was flagged by their internal security. In fact Camelot immediately suspending the accounts of the players concerned and rapidly began the process of contacting the 26,500 individual to help them re-activate their accounts securely.
“We do not hold full debit card or bank account details in National Lottery players’ online accounts and no money has been taken or deposited. However, we do believe that this attack may have resulted in some of the personal information that the affected players hold in their online account being accessed,” the operator said, in a refreshingly transparent statement. Camelot also said it was working with the National Crime Agency and the National Cyber Security Centre, a new division of GCHQ, to investigate the incident in addition to notifying the ICO of the BREACH.
So what has happened?
Despite what you may have read, Camelot are victims of a data breach NOT a hack- Millions of emails are on sale in various markets within the DarkNet marketplaces – these have been harvested from hundreds of hacks of different organisations, buying email addresses and passwords is as organised as buying legal marketing data, you can simply select the region that you wish the emails to have come from and supply payment (usually Bitcoin) The biggest issue is that so many people re-use their password across many websites and actually fail to change their credentials for all sites even after a hack on a different, singular site. It would appear that the cyber criminals launched a sustained attempt to utilise credentials obtained elsewhere to access Camelot accounts, think of it like you lending a spare set of car keys to a friend whom then loses your keys, you then do not bother to change the locks on the car and it is subsequently stolen with the stolen keys – who is to blame? Certainly not the multistory carpark owner in which your car was parked at the time!
The most frustrating thing about the coverage is the plain lack of intelligence around the reporting of this incident – which for the majority of reports are simply wrong – calling this a “hack” displays a real lack of knowledge and understanding of digital fundamentals, stupidly misrepresenting the incident will only make other companies to whom a no-fault breach has occurred, think twice before being completely transparent and responsive in the way Camelot has been, companies will be more likely to take the Tesco Bank route of burying their head in the sand and then misleading customers even after them hack had been admitted – or perhaps we prefer the Talk Talk method of completely ignoring the issue until faced with a potential consumer revolt? Either way – criticising Camelot who appears to have acted responsively and sensibly at this stage is foolish and counter productive.
One of the most startling activity is to see how so called experts and professionals seem to be quite happy linking to and sharing mainstream media clickbait style misreporting. This is worrying, as in the past blogs and websites of knowledgeable individuals and companies have been an important part of knowledge sharing which facilitates education and knowledge growth, it would seem that this has changed for many so-called experts who dilute their possible knowledge bank when simply linking to a poorly written, confused or sensationalist piece of so called journalism from the “experts” at the Guardian, Daily Mail or the Sun.
At a time when technology companies are being critiscised for “fake news”, it is imperative that shares, blogs and sites are completely transparent with the subjects they are addressing – clickbait journalism has no place in the forum of Digital Knowledge and is unwelcome, so here’s a suggestion for you – have another look at the streams, shares, blogs and profiles of the “experts” you follow and trust – if they are guilty of regurgitating clickbait headlines or linking to mainstream articles which are clearly written by non specialist “journalists” then do yourself and everyone in the Digital Industry a favour – unfollow them, stop visiting their blogs & sites. We have enough issues with the mainstream media – without feeding swelling the ranks of digitally misinformed followers by so called experts in our own ranks.
Remember, if the email address and password you used on Tumblr – where 65m passwords were stolen from in 2013 or Yahoo where a staggering half a billion records were stolen – are the same as you used on Camelot, you left the keys to your Camelot Account laying around, waiting to be stolen – individuals failure to listen to repeated warnings can hardly be blamed on a company whom does its best to keep your data safe and responds excellently to suspicious behaviour it picks up upon. Blaming such an incident on a “hacker” simply allows us to blame a faceless description that many do not understand rather the lay the blame where is actually lies – with the user.







