Get all your news in one place.
100’s of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

Nokia confirms data breach leaked third-party code, but its data is safe

Cyberattack.

  • Nokia investigation confirms cyberattack with a third party
  • The company says its own data is secure
  • It will continue to monitor the situation

Nokia has confirmed a recent data breach did indeed happen, but did not affect its own internal data.

The telecoms giant said it had completed its initial investigation into the incident, confirming that a breach had occured, but that its systems, and data, is intact.

"Our investigation has found no evidence of any of our systems or data being impacted. Our investigations point to a 3rd party security incident, related to a single customized software application," the company told BleepingComputer.

End of life

An infamous data leaker known as IntelBroker recently posted a new ad on an underground forum, advertising a stolen archive apparently containing data from the telco giant.

The archive was taken from a third party, and was said to contain a large collection of Nokia source code, with the hacker claiming to have stolen Nokia software, SSH keys, RSA keys, BitBucket logins, SMTP accounts, webhooks and hardcoded credentials.

IntelBroker claims to have breached a third-party vendor via a SonarQube server. There, they downloaded sensitive files belonging to multiple companies, including Nokia.

“We have found no evidence that this 3rd party incident would in any way endanger critical Nokia systems or data, including source code, customized software, or encryption keys. Our customers are in no way impacted, including their data and networks,” Nokia added.

The source code IntelBroker leaked was for an application that the third-party built, for a client of Nokia’s. It was supposed to work on only one network, and will not work elsewhere, it was added. No Nokia code was found inside, either.

The company concluded its statement by saying it was “closely monitoring” the situation.

IntelBroker is reportedly a Serbian hacker who has been active since October 2022, and has a history of high-profile attacks. More than 80 separate leaks have been posted to online forums by IntelBroker to date, with targets including companies and organizations such as AMD, Apple, Europol and HPE.

Via BleepingComputer

You might also like

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.