Reports suggest that the cyber-attack on TalkTalk’s (LON:TALK) web site has been followed by a ransom demand from the hackers.
TalkTalk said it has received a demand for money from a company purporting to have perpetrated the security breach.
Police have launched a probe into the cyber-attack in which personal customer data was potentially hacked.
TalkTalk said London's Metropolitan Police Cyber Crime Unit had begun the investigation on Thursday following a "significant and sustained cyber-attack".
The company reported the inquiry was ongoing, but there was a chance that names, addresses, dates of birth, phone numbers, email addresses, TalkTalk account information, credit card details and/or bank details had been compromised.
TalkTalk said it was continuing to work with leading cyber-crime specialists and the police to establish exactly what happened and the extent of any information accessed.
Chief executive Dido Harding said: "TalkTalk constantly updates its systems to make sure they are as secure as possible against the rapidly evolving threat of cyber crime, impacting an increasing number of individuals and organisations.
"We take any threat to the security of our customers' data extremely seriously and we are taking all the necessary steps to understand what has happened here.
"As a precaution, we are contacting all our customers straight away with information, support and advice around yesterday's attack."
The Guardian newspaper reported that Adrian Culley, a former detective at Scotland yard’s cyber-crime unit, believes the hack appears to be the work of Islamic militants.
A group naming itself “TalkTalk Hackers” published on a site commonly frequented by hackers what it claimed was a sample of dozens of email addresses and national security numbers as proof of the attack.
On its web site, TalkTalk said it has contacted the major banks, who will be monitoring for any suspicious activity on the accounts of TalkTalk customers.
“We are offering a year's free credit monitoring for all of our customers and will be contacting customers with the details. Noddle (www.noddle.co.uk) also allows free access to your credit report for life,” a TalkTalk statement revealed on the company’s web site.
Mark Skilton, of Warwick Business School, a Professor of Practice of Information Systems, said: "Large scale data theft is increasingly big business for professional cyber criminals. The value of personal identity data records and account details is increasingly high as it can be used in masquerading identity to commit theft of other data; or give direct access to personal bank account money and fraudulent transactions.”
Professor Skilton said that if TalkTalk had not encrypted all of its data then it suggested lessons have not been learnt on controlling sensitive content.
"Talk Talk have alerted banks to the theft but this is too late as it will already be on the move in the cyber-criminal community. All that can be done now is to rapidly change the ‘locks’ and identity management of the millions affected but that’s not easy,” Professor Skilton asserted.
“For customers, if your Talk Talk username is your email address and you use that email and password combination anywhere else, change it immediately wherever you use it, and make your Talk Talk password unique to that site from now on. The attackers may still be in there,” he advised.
Shares in TalkTalk were off 2.4% at 262p in late afternoon trading.