Faithless fans have personal data stolen after band's website hacked

Exclusive: Experts fear breach of faithless.co.uk, affecting some 18,000 people, will be repeated on other music websites

Jonathan Owen
Monday 11 January 2016 14:38 EST
Comments
Faithless are widely regarded as pioneers in British dance music
Faithless are widely regarded as pioneers in British dance music (BBC)

Your support helps us to tell the story

From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.

At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.

The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.

Your support makes all the difference.

Thousands of British music fans have had their personal data stolen and are in danger of being targeted by online fraudsters, after the website of dance act Faithless was hacked.

Experts fear the breach of faithless.co.uk, affecting some 18,000 people, will be repeated on other music websites.

The hack, in which a single piece of malware was uploaded via a common hacking technique known as an SQL injection, was able to get past the website’s defences.

It was spotted by internet security firm CyberInt, which monitors hacking activity. The breach became apparent last September but was only confirmed by the cyber security company yesterday.

“We have a system that collects cyber threat intelligence in real time, and as part of our work we uncovered a Faithless database being sold on the Dark Web, and we flagged it up with them,” Elad Ben-Meir, the company’s vice president of marketing, told The Independent.

“I think they fixed the issue but they didn’t quite go out and tell anyone that, so that leaves their fans, about 18,000 people, unaware that their private information has been compromised,” he added.

Faithless, regarded as pioneers in British dance music, have sold some 12 million records worldwide since they formed 20 years ago. The group, whose members go by the names Maxi Jazz, Sister Bliss and Rollo, are best known for their hits “Insomnia” and “God Is a DJ”.

The management company which represents the band did not respond to requests for comment yesterday.

In the meantime, users of the Faithless website remain at risk of online fraud, according to CyberInt.

Their data, which is understood to include personal email addresses and passwords used to access the site, is now being sold on the Dark Web.

“Although the actual details for sale on the Dark Web are likely to sell for only a few hundred dollars, they could end up costing unlucky music fans far more,” warned Mr Ben-Meir.

Even limited information, such as an email address combined with details of someone’s musical tastes, can be valuable to cybercriminals. “The fraudster will send the fan a spoof email asking the victim to open an attachment or follow a link to a fake phishing website. Once the attachment is opened or the link clicked, the hacker could gain additional information about the fan or event take control of the fan’s computer,” saud Mr Ben-Meir.

Music websites are attractive to cybercriminals as there is often a relationship of trust between fans and performers. Mr Ben-Meir suggests that the Faithless hack “could signal the start of a new trend of attacks on the UK’s £3.5 billion a year music industry,” he added.

Sony Music has been repeatedly hacked in the past five years, and the websites for artists such as Lady Gaga and Jessie J have also been successfully targeted.

And the theft of data from the Faithless website is one of a series of high profile hacks in recent months, which have included the BBC news website and its iPlayer service, the Wetherspoon pub chain, telecom firm Talk Talk, and dating website Ashley Madison.

Join our commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Comments

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in