Skip to content
The Cyber Security Place

Three quarters of them had already left

Event dated 1 September 2026 · Published 2 September 2026 · 3 sources

Eastlink told customers at the end of August 2026 that a breach of its account portal affected 75,000 current and former customers, exposing names, contact details, account numbers and PINs, with credit card data considered very unlikely to have been reached. The proportion is the part worth keeping: only about 18,000 of those people were still customers — fewer than 5% of the active base — which means roughly 57,000 had already left. The company found it itself, through unusual log-in activity in its own portal. Three quarters of the harm came from records the business no longer had a use for.

Every discussion of reducing breach impact eventually arrives at deleting things, and then moves on, because deletion produces no dashboard and nobody is promoted for it. It is the recommendation that appears near the end of the list and gets done last or never.

This incident supplies the number that argument has always lacked. Not an assertion that old data is a liability — a ratio. For every person harmed who had a current relationship with this company, roughly three were harmed who did not.

Why the records of people who left are still there

For reasons that are each defensible. Tax and regulatory rules require keeping billing records for years. A former customer may return, and recognising them is better service than starting again. Disputes surface late. Analytics on churn need history. Nobody decided to keep the data of fifty-seven thousand departed customers; a series of sound smaller decisions produced it.

What is much harder to defend is those records sitting in the same system that serves live account logins. The obligation is to retain, not to keep reachable from the internet by anyone who can authenticate. Those are different requirements and are met by the same database in most organisations because separating them is work with no visible benefit until a week like this one.

A PIN on a telecoms account is not a minor field

Reporting lists names, contact details, account numbers and PINs. In most contexts a PIN reads as a low-grade secret. On a telecommunications account it is frequently the control that stands between an attacker and a transfer of the phone number itself.

That matters because the number is where verification codes arrive. Somebody who moves a number receives the messages that reset everything else — which is the mechanism this site described in May, when a relayed one-time code defeated the advice built around it. Here the code does not need relaying, because the attacker has the handset's number.

For former customers the exposure is stranger still. Their PIN protects an account they no longer hold, but the name, address and telephone number attached to it remain useful for convincing somebody at a different provider that the caller is who they claim.

Twelve months of monitoring for data with no expiry

The company offered affected people a year of identity monitoring, which is the standard remedy and is better than nothing. It is also a fixed-term response to an exposure with no term: a name, an address and a former account number do not become less usable in month thirteen.

The offer makes most sense read as what it is — a gesture that acknowledges harm and covers the period in which fraud most often follows a breach. It is not a remedy in the sense of restoring the position, and no available product would be.

The part that went right

They found it themselves. Unusual log-in activity in their own account system prompted an internal investigation, and notification began within days rather than months. After a year of pieces describing organisations that learned of their own incidents from an extortion site or a journalist, that deserves stating plainly.

It is also the reason the numbers in this piece exist at all. An organisation that detects its own breach early can say how many people and which fields; one that learns late is still months from being able to answer either question.

The instruction this leaves

Ask what proportion of the records in your customer-facing systems belong to people who are no longer customers. Most organisations have never calculated it, and the answer is usually larger than anybody expects, because leaving is silent and deletion requires a decision.

Whatever that proportion is, it is the share of your next breach that could have been prevented by housekeeping rather than by security — and it is the cheapest reduction available to any organisation, in a year that has otherwise offered very few.