HOME     MENU     SEARCH     NEWSLETTER    
THE ENTERPRISE SECURITY SUPERSITE. UPDATED 14 MINUTES AGO.
You are here: Home / Network Security / Huge Hack Hits Vodafone Customer Data
Massive Hack on Vodafone Germany Affects 2 Million Users
Massive Hack on Vodafone Germany Affects 2 Million Users
By Jennifer LeClaire / Enterprise Security Today Like this on Facebook Tweet this Link thison Linkedin Link this on Google Plus
PUBLISHED:
SEPTEMBER
12
2013
The personal details of about 2 million Vodafone Germany customers have been exposed in a hack that's making international headlines. According to the company, hackers tapped into an information pool of addresses, bank account numbers and dates of birth.

"Vodafone Germany has world-class security systems that are constantly updated and upgraded to block new emerging threats. However, this attack was highly complex and conducted with inside knowledge of our most secure internal systems," the company said in a statement.

"As soon as we discovered the incident we took all necessary steps to stop the attack, minimize any adverse impact for our customers and notify all relevant German authorities," company officials said. "We are sending our sincere apologies to everyone affected for any disruption caused."

We're All in Danger

We caught up with Chester Wisniewski, a senior security advisor at Sophos, to get his analysis on the latest breach. He told us whenever personally identifiable information is purloined by online criminals, it increases the risk to the victims, despite what the vendor might claim.

"This advice doesn't just apply to the two million who we know had their information stolen. It applies to everyone, all the time. Many criminals might try to use this information offline as well as online, so be cautious of any suspicious activity, like incoming phone calls claiming to be your bank," he added.

On-Premise Security Fails

We also asked Kevin O'Brien, an enterprise solution architect at CloudLock, for reaction to the Vodafone hack. He told us it reveals as yet another example of how and why on-premise data security models have failed to keep up with an increasingly interconnected world: Servers that contain critical data, such as personally identifiable information that was stolen in the Vodafone hack, should not be accessible on the public Internet.

"The problem is that organizations cannot keep up with the ever-changing set of vulnerabilities, patches, and zero-day exploits that leave this kind of information at risk," O'Brien said. "While we don't yet know the details of how this particular server was compromised, it is fair to guess that a known issue was used to gain access -- an outdated version of either the OS or some piece of software running on the system, through which the attacker was able to gain adequate permissions to read and ultimately get away with high-value information." (continued...)

1  2  Next Page >

Tell Us What You Think
Comment:

Name:

Charles:
Posted: 2013-09-17 @ 5:36am PT
Disappointing that you didn't do any fact checking on this article and allowed a vendor to take control of the article. Now the article is an advertisement for cloud storage - but that wasn't the issue on this compromise. It was an outsourced admin who did the damage. He would have had access to cloud storage too. Privileged users simply shouldn't have access to data. They don't need it to do their jobs. Even more so in the cloud. Cloud is great and has its place - just not relevant to this story.

Like Us on FacebookFollow Us on Twitter
TOP STORIES NOW
MAY INTEREST YOU
High Quality CRM Data: Prevent, detect and fix errors at the point of data entry for Dynamics CRM. Trillium Software helps you achieve an accurate, synchronized, single view of customers. It's time to trust your data. Take a product tour and read CRM Analyst opinions here.
MORE IN NETWORK SECURITY
Product Information and Resources for Technology You Can Use To Boost Your Business
© Copyright 2014 NewsFactor Network, Inc. All rights reserved. Member of Accuserve Ad Network.