
The data was almost certainly obtained by using usernames and passwords first stolen from gaming website XSplit three years ago to log onto O2 accounts.
When the login details matched, the hackers could access O2 customer data in a process known as “credential stuffing”.
O2 says it has reported the case to police, and is helping the inquiry.
It is highly likely that this technique will have been used to log onto other companies’ accounts too.
Most Popular
-
1
Residents object to rooftop pool planning application in Horbury
-
2
Don’t Pay UK: Expert warns why you should NOT cancel energy bill direct debits
-
3
Yorkshire Water announces hosepipe ban
-
4
£2.2million worth of drugs seized in Wakefield
-
5
Wakefield Pride 2022: Full list of road closures for Sunday's celebration of diversity
All the O2 account holders whose details have been seen have been informed, with many saying they had used the same login for other online accounts.
O2 said in a statement: “We have not suffered a data breach. Credential stuffing is a challenge for businesses and can result in many company’s customer data being sold on the dark net.
“We have reported all the details passed to us about the seller to law enforcement and we continue to help with their investigations.”