Search/vodafone
Vendor

vodafone

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
vodafone mobile@work
Connections
18 relationships
Exclusive: Linux Foundation's Akrites to Go Live in September
A major industry coalition set up to defend critical open-source software against AI-enabled cyber threats is expected to operationalize its vulnerability disclosure and remediation platform in September, Infosecurity has learned. The initiative, called Akrites, was launched at the end of June 2026 by the Linux Foundation, the Open Source Security Foundation (OpenSSF) and over 20 founding members. These include AI frontier labs Anthropic and OpenAI; cloud and tech giants like Amazon Web Services, Cisco, Google, Microsoft and its subsidiary GitHub, IBM and its subsidiary Red Hat and NVIDIA; cybersecurity firms like Chainguard, Endor Labs and Zscaler; and large enterprises, such as Citi, JPMorganChase, Ericsson and Vodafone. Each member of the coalition must donate between one and 10 engineers to the project and pay membership fees based on which of the three membership tiers they chose – Associate, General and Premier –, each corresponding to a level of benefits. At launch, the Linux Foundation announced two major missions for the initiative: Establish a shared security incident response team (SIRT) for mitigating and remediating vulnerabilities in open-source packages and libraries Develop a standardized coordinated vulnerability disclosure (CVD) process, built on confidentiality-first principles and industry-standard tooling Infosecurity spoke to Christopher ‘CRob’ Robinson, OpenSSF’s CTO and chief security architect, who was appointed as CTO of Akrites in June. He described Akrites’ sole mission as “coordinating AI-enabled vulnerability reports to upstream open-source maintainers so that the fixes are available to the whole ecosystem.” He said the team responsible for the initiative’s tooling, including the vulnerability management and SIRT platform, had now produced “the first draft of the tool chain.” He revealed that the initiative’s main platform will be based on Carnegie Mellon University's Vulnerability Information and Coordination Environment (VINCE), a vulnerability management platform developed in 2020 by the Computer Emergency and Response Team Coordination Center (CERT/CC), a unit of the university’s Software Engineering Institute (SEI). “We have a substantial amount of additional capabilities leveraging large language models (LLMs) to do deduplication, patch creation and more,” added the Akrites CTO, who confessed he’s already received thousands of vulnerability reports after two months of launching the project, an estimated 30% of these are duplicates. “Today, we’re bringing in some additional experts from the Akrites members to go through and do a penetration test and a security audit and then we’ll be augmenting the tools to allow the input of a combination of real and synthetic data through the system to make sure it functions as we design,” Robinson explained. When ready, the finished platform will be open-sourced and available for anyone to use for their own purposes. Additionally, Robinson said the Akrites-run platform is expected to “go live” and “start taking automated vulnerability reports” some time in September. “I have been trying to do something like Akrites my whole career,” he said. “I feel right now we have the tools, the willpower and access to the technical experts, so I’m very optimistic on our chances that we’re going to be able to provide a very valuable service to the global open-source ecosystem.” Stay tuned to Infosecurity for further updates on Akrites and similar initiatives to tackle the explosion of AI-enabled vulnerability reports in open-source projects. Image credits: Linux Foundation / IB Photography / Shutterstock.com
infosecurity-magazine.comAug 19, 2026extracted
Hacker claims millions of records stolen from corporate Azure tenants
Hacker claims millions of records stolen from corporate Azure tenants A threat actor known as “TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), according to Hudson Rock. Over the past week, the threat actor has posted a string of large internal employee directories on cybercrime forums, claiming that each was pulled directly from the victim organization’s Azure tenant. In addition to McDonald’s, Vodafone, Kyndryl, and TCS, the alleged victims include HCL Technologies, InterContinental Hotels Group (IHG), Gap Inc., Hexaware Technologies, and Wyndham Hotels. Leaked data appears authentic The volume of data on offer is large. McDonald’s tops the list with an estimated 1.7 million records, followed by TCS at around 800,000, Vodafone at roughly 425,000, and HCL at about 250,000. IHG, Kyndryl, Gap, Hexaware, and Wyndham round out the rest, with counts ranging from several thousand to over 170,000 records apiece. Hacker forum post advertising the McDonald’s employee data leak (Source: Hudson Rock) Hudson Rock researchers examined samples of the leaked data and found corporate email addresses and field names consistent with a standard Azure directory export, indicating that the material is likely authentic. “While the data is highly likely authentic, it is not conclusive how this campaign is being carried out,” Hudson Rock said. “However, the exact intrusion vector remains unknown. This mass exfiltration could be the result of active Infostealer infections compromising employee session tokens, highly successful phishing campaigns yielding administrative access, a lack of strict Multi-Factor Authentication (MFA) on specific tenant portals, or potentially an abuse of a third-party API/Integration that had excessive read privileges across multiple environments. The sheer scale and speed of these dumps suggest a systematic, automated approach once initial access is achieved,” they added. According to Hudson Rock, each dump includes employee IDs, job titles, departments, manager and direct-report information, group memberships, service accounts, and, in some cases, the names of accounts holding Global Administrator privileges. “The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations,” researchers warned. Hudson Rock was careful to note that it has no definitive confirmation of which specific credentials were used to break into these organizations, only that compromised Azure logins tied to most of the named companies were circulating as a result of infostealer infections. “Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure. If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises,” researchers noted. TCS responds to employee data exposure claims One of the nine named companies, TCS, filed a statement with the Bombay Stock Exchange on August 10 after receiving threat intelligence alerts about the possible exposure of employee data. The company stated that it “has not found any credible evidence of a breach” of its own systems or customer environments. TCS reported that the referenced information appears to be more than four years old and limited to basic employee details such as names, IDs, job titles, and contact information, adding that nothing points to customer data, customer systems, or its own operational systems being affected. “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years. Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely.” “The Company will continue to assess any new information that becomes available and take appropriate action, if required,” it concluded.
helpnetsecurity.comAug 18, 2026extracted
Crook hawks millions of records allegedly plundered from corporate Azure tenants
A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans nine organizations and is being advertised for sale by a threat actor using the name "TheHatman," according to research published by Hudson Rock. McDonald's accounts for the largest alleged dataset on TheHatman's shopping list, with 1.7 million records purportedly up for grabs. Another 800,000 records supposedly come from Tata Consultancy Services, 425,000 from Vodafone, and 250,000 from HCL Technologies, with IHG Hotels & Resorts, Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels & Resorts rounding out the haul. Hudson Rock assessed the data as "highly likely authentic," citing corporate email addresses and structures consistent with exports from Microsoft Azure directory services. The records allegedly contain considerably more than names and work email addresses. Samples reviewed by the security shop reportedly include phone numbers, physical addresses, employee IDs, job titles, departments, office locations, reporting structures, group memberships, and service account details. Some records also reportedly identify accounts with Global Administrator privileges, potentially handing attackers a useful map of whom to target next. Even if the passwords aren't included, knowing who holds the keys to the kingdom makes for a handy phishing shortlist. How TheHatman allegedly obtained the information remains unclear. The attacker claims to have used compromised credentials, but Hudson Rock could not independently establish the initial access vector. It floated several possibilities, including credentials or session cookies stolen by infostealer malware, phishing, weak or absent multifactor authentication, and overly permissive third-party applications. Hudson Rock said its infostealer database contained compromised Microsoft cloud credentials associated with most of the named companies, although it could not link those credentials to TheHatman's alleged access. "Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure," said Hudson Rock. "If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises." The Register contacted all the organizations named by Hudson Rock to ask whether they were breached, whether the advertised data is authentic, and how any unauthorized access occurred. We've also asked Microsoft whether it is aware of a wider campaign targeting Azure or Entra customers. Tata Services sent The Register the statement it made to India's stock exchange [PDF] saying that the “Company has received threat-intelligence alerts alleging possible exposure of certain employee information." It added: The Company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments. The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted. “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years. Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely." It said: “The Company will continue to assess any new information that becomes available and take appropriate action, if required. The Company remains committed to maintaining the security and resilience of its systems and to protecting the information entrusted to us.” TheHatman claims to have the data. How it might have walked out of nine corporate directories is the part nobody has explained yet. ®
theregister.comAug 17, 2026extracted
Fortune 500 Companies Hit in Azure Data Theft Campaign
A threat actor is selling data allegedly stolen directly from the Azure tenants of several Fortune 500 organizations. Using the moniker ‘TheHatman’, the threat actor has been offering millions of records apparently stolen from well-known brands such as McDonald’s Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. According to the threat actor, the data was exfiltrated from Azure/Entra instances using leaked credentials. The data contains internal employee directories that, based on the identified email addresses and field names that match Azure directory exports, appear legitimate, Hudson Rock says. The McDonald’s dump is the largest, containing over 1.7 million records, followed by the TCS dataset, with 800,000 records, Vodafone with 425,000, HCL Technologies with 250,000, and IHG with 185,000. “Across all the affected tenant dumps, the leaked fields consistently include foundational corporate directory attributes,” Hudson Rock says. The exfiltrated information includes employee names, corporate email addresses, addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts, highly privileged account records, and more. “The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations,” Hudson Rock notes. According to the company, credentials compromised in a targeted infostealer campaign were likely used to exfiltrate the data. Not only did Hudson Rock identify stolen credentials linked to most of the affected organizations, but the victimology also suggests a targeted attack. “The campaign impacts multiple global enterprises across IT services, hospitality, telecommunications, retail, and logistics,” the company notes. Hudson Rock also points out that the stolen data poses an immediate threat to the victim organizations, as it allows attackers to map internal reporting structures and high-value targets, and enables them to launch convincing spear-phishing and business email compromise (BEC) attacks. Related: 1.6 Million Likely Impacted by RingCentral Data Breach Related: 14,000 Trezor Customers Impacted by Data Breach at ShipMonk Related: Trivy, Not LiteLLM Behind the 2,500 Org Compromise Related: Massive Password Spray Campaign Targeting Azure CLI
securityweek.comAug 17, 2026extracted
UK Government Launches Cyber Resilience Pledge, Claiming 60+ Signatories
The UK government has claimed over 60 businesses have signed up to a new initiative designed to improve the cyber resilience of British organizations. The Cyber Resilience Pledge was first trailed at the government’s CYBERUK conference in Glasgow in April, alongside a £90m ($120m) cash injection. Signatories now include Marks & Spencer, Nationwide, ITV, Microsoft UK, Cloudflare, Deloitte LLP, Accenture UK and Vodafone Group, the government claimed. The voluntary scheme requires signatories to commit to: Making cybersecurity a board-level responsibility, by implementing the Cyber Governance Code of Practice and ensuring all members complete the NCSC’s Cyber Governance Training Registering for the NCSC’s free Early Warning alert service Taking a “risk-based approach” to requiring Cyber Essentials certification across their supply chain The pledge is designed mainly for medium and large organizations. However, the hope is that they will be able to improve baseline security posture across a much larger swathe of businesses by forcing suppliers to sign up to Cyber Essentials. Whether that actually happens has yet to be seen. Data released last year revealed that only around 35,000 organizations were signed up to the best-practice cyber framework, out of over five million businesses across the country. Businesses with a turnover of under £20m ($27m) that are Cyber Essentials certified are entitled to free cyber-liability insurance, including professional incident response support, the NCSC has reminded firms in the past. A Multi-Pronged Approach The pledge is one of several initiatives the government is pressing ahead with to try and improve corporate cyber resilience. A Cyber Security and Resilience Bill will introduce new requirements for certain critical national infrastructure (CNI) providers and a new Cyber Action Plan aims to enhance resilience and accountability across central government. The Cyber Governance Code of Practice is another voluntary effort, designed to help board members govern cyber risk the same way they treat other core business risks. As part of its Cyber Resilience Pledge, the government announced a Cyber Charter with its 39 strategic suppliers, which invites them to sign up to the pledge. So far, 20 have done so. “As AI reshapes both the threats we face and our response to them, stronger board-level accountability and supply chain security are how the UK stays ahead,” said Microsoft UK CEO, Darren Hardman. “Microsoft has been a cybersecurity partner to the UK government for more than 20 years, and we’re proud to sign the Cyber Resilience Pledge, using AI to help defend the UK’s critical national infrastructure, public services and businesses against cyber-attacks.” Technology secretary Liz Kendall added that cyber resilience has moved from an IT matter to a business imperative. “The steps in this pledge are practical, achievable and proven to make a difference,” she added. “Today’s signatories are leading the way, and I encourage organizations across the UK to follow their example.”
infosecurity-magazine.comJul 7, 2026extracted
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January and May 2026. The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is also known as Chatty Spider, Luna Moth, and Silent Ransom Group (SRG). "UNC3753 leverages voice phishing (vishing) and social engineering deception techniques to achieve remote access into corporate environments," researchers Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, and Tyler McLellan said. "Using pretexts such as data migration or invoice-related emails, the threat actors initiate phone conversations posing as IT support and convince targets to host screen-sharing sessions and download remote monitoring and management (RMM) utilities." Upon gaining access, the threat actors have been found to either carry out direct searches to locate and exfiltrate files of interest or deceive the victim into carrying out the actions on their behalf. Stolen information includes proprietary legal agreements, personally identifiable information (PII), and financial records. In some instances, the attackers have accessed victims' systems in person, echoing an advisory issued by the U.S. Federal Bureau of Investigation (FBI) last month. These physical intrusions involve the threat actors posing as IT technicians to enter corporate offices and attempt to steal data using removable USB media. "By sending someone in-person to the victim's location to facilitate the intrusion, SRG actors exfiltrate data to an external hard drive or USB drive inserted by the threat actor into the victim's computer," the FBI said of the new escalation in UNC3753's capabilities. Google said UNC3753 shares tactical overlaps with UNC2686, a threat cluster previously known for carrying out BazarCall-style campaigns in 2021. Although the group has been observed deploying LockBit Black ransomware in the past, it has mainly focused on extortion-only operations since 2022, pressuring victims to pay up or risk getting their data published on the LEAKEDDATA data leak site. Both UNC3753 and UNC2686 are assessed to be offshoots of the now-defunct Conti ransomware gang, with early iterations of the campaigns using subscription cancellation lures as part of callback phishing attacks that aim to install remote access software on victims' machines. Beginning around March 2025, the hacking crew has impersonated internal corporate IT help desk staff to trick victims into joining a screen-sharing session on enterprise communication platforms like Zoom, Microsoft Teams, or Quick Assist under the guise of addressing a security issue helping with a corporate data migration project, effectively bypassing traditional security controls. "The threat group frequently initializes campaigns using benign, invoice-themed email lures sent from actor-controlled consumer email accounts," Google said. "These messages contain no active links or malicious attachments. Instead, they typically contain a brief, generic message. The primary purpose of these emails is to establish a pretext, raising the target's internal security concerns so they are more susceptible to follow-up voice calls." Once a session is established, the attackers attempt to establish a persistent foothold by guiding the victims to install legitimate remote desktop software like AnyDesk, Bomgar, SuperOps RMM, or Zoho Assist. Instructions to install these programs are shared via a legitimate service called "privnote[.]com," which allows users to send notes that self-destruct after being read by the recipient. UNC3753 has also been observed establishing Zoom sessions directly on targets' personal laptops to access corporate virtual desktop infrastructure (VDI) and burrow deeper into corporate file systems with the goal of enumerating local and cloud directories, crawling mapped network drives, and harvesting data from highly sensitive folders, including those related to tax filings, audits, corporate client agreements, and Social Security numbers (SSNs). In the final stage, the captured data is sent to the threat actors via WinSCP or Rclone, or to email addresses controlled by the threat actor from the target's mailbox. This is followed by the attackers sending an extortion demand in the form of an email message, typically within 30 minutes of exiting the target environment. The email messages give victims a three-day deadline to initiate ransom negotiations. They also threaten to call and email target employees and external clients directly to notify them of the data breach should they remain unresponsive, not to mention publish the entire stolen information on the data leak site. In many incidents investigated by Google's threat intelligence and incident response teams, the end-to-end operation from initial contact to data extortion is said to have occurred within a single business day. The fast-tempo operational model is exemplified by the fact that the attackers initiate data searches, staging, and theft in under an hour. "Legal services firms represent high-value targets for extortion actors. They maintain concentrated repositories of extremely sensitive client transaction files, merger and acquisition plans, client trade secrets, and corporate regulatory reports," Google said. "Threat groups recognize that legal entities are subject to heavy reputational and regulatory exposure and may be highly motivated to resolve extortion situations quietly to protect their professional standing. Threat actors recognize that targeting the human element - specifically using voice-guided social engineering-enables them to easily bypass robust technical perimeters, web security gateways, and MFA configurations." The findings coincide with a new report from Resecurity about the threat actor's use of DNS Fast Flux network infrastructure across various countries in Latin America, Eastern Europe, Central Asia, Middle East/Africa, East Asia, and the Caribbean to make its domains harder to block - business-data-leaks[.]com, the data leak site that lists close to 100 victim organizations as of June 2026 ep6pheij[.]com, which stages the stolen data per victim "By changing the DNS records and using short Time-To-Live (TTL) values, attackers make their malicious infrastructure resilient against takedowns," the cybersecurity company said. "Both domains operate on a fast-flux network backed by a botnet spread across 18 countries and 22 ISPs. The two domains share 50-60% of their bot pool, confirming a single threat actor operates both. The infrastructure contains zero datacenter or hosting IPs - every node traces back to a consumer ISP (e.g., Telecentro, Mega Cable, Vodafone) and is flagged as residential or mobile IP address."
thehackernews.comJun 8, 2026extracted
18th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Vodafone, a major international telecom, has sustained a source code leak claimed by the Lapsus$ extortion group. The company confirmed limited access to GitHub files through compromised third-party development software, while stating that customer data and core network infrastructure were not affected by the incident. Cryptocurrency platform THORChain, based in Switzerland, has encountered a security breach that led to the theft of about $10.7M. Trading was halted after one of six vaults was compromised, and the company said losses were limited to protocol-owned assets across several blockchains. West Pharmaceutical Services, a global manufacturer of drug delivery components, has experienced a ransomware attack that disrupted shipping, manufacturing, and shared service functions. The company disclosed that some systems were encrypted and data was stolen, but no ransomware group has publicly claimed responsibility. Foxconn, a global electronics manufacturer, has confirmed it was hit by a cyberattack on its North American operations after the Nitrogen ransomware group claimed to have stolen 8TB of data. The company confirmed disruption at some factories and said affected facilities were resuming normal production. AI THREATS Researchers unveiled ‘Claw Chain’, four vulnerabilities in OpenClaw, an autonomous AI agent platform, that allow attackers to bypass sandbox controls, expose restricted files, leak secrets, and gain owner-level access. The flaws include the critical CVE-2026-44112, rated CVSS 9.6. Researchers developed an AI-assisted macOS kernel exploit that bypasses Apple’s Memory Integrity Enforcement on M5 chips and grants full system control on macOS 26.4.1. Anthropic’s Mythos Preview reportedly accelerated bug discovery, and the findings were privately reported to Apple before public disclosure. Researchers detailed how threat actors abuse Vercel’s AI website generator, v0.dev, to mass-produce realistic phishing pages mimicking brands such as Microsoft and Spotify. The campaigns utilize Telegram bots to capture credentials and payment details in real time. Researchers found a popular Hugging Face repository hiding Windows-targeting malware after it amassed over 200,000 downloads. The package posed as OpenAI’s privacy filter and installed an infostealer that harvested browser passwords, cookies, SSH keys, VPN configurations, and cryptocurrency wallets before exfiltrating the data. VULNERABILITIES AND PATCHES Two Windows zero-day vulnerabilities, YellowKey and GreenPlasma, affect Windows 11 and recent Windows Server versions. YellowKey allows BitLocker bypass through Windows Recovery Environment with physical access, while GreenPlasma abuses the CTFMON framework to escalate privileges to SYSTEM. Proof-of-concept code is public, and the vulnerabilities are still unpatched. F5 has fixed CVE-2026-42945, a critical memory flaw in the NGINX rewrite module affecting versions 0.6.27 through 1.30.0. The 18-year-old bug enables denial of service and, under specific configurations, possible remote code execution. Public exploit code requires memory protections to be disabled. Check Point IPS provides protection against this threat (Nginx Heap Overflow (CVE-2026-42945)) Cisco has addressed CVE-2026-20182, a critical authentication bypass in Catalyst SD-WAN controllers that is being actively exploited. The flaw allows remote, unauthenticated attackers to gain full administrative control of affected systems. CISA ordered federal agencies to patch vulnerable devices following Cisco’s fixes. Apple has released security updates for CVE-2026-28819, an out-of-bounds write flaw in the Wi-Fi component affecting iOS, iPadOS, and macOS. Successful exploitation could allow an app to execute code with kernel privileges. The issue was addressed with improved bounds checking. THREAT INTELLIGENCE REPORTS Check Point Research has analyzed an internal leak from The Gentlemen ransomware operation, exposing chats, infrastructure details, affiliate roles, and ransom negotiations. The report links the zeta88 account to the administrator, maps 8 affiliate TOX IDs, and details the use of Fortinet and Cisco vulnerabilities as well as NTLM relay and OWA/M365 for initial access in attacks. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Check Point Research has summarized Q1 2026 ransomware trends, recording 2,122 leak-site victims, which is the second-highest Q1 on record, and renewed consolidation. The top 10 groups were responsible for 71% of victims. Qilin led with 338 victims, The Gentlemen rose to third, and LockBit 5.0 returned with 163 victims. Check Point Research have quantified a World Cup 2026-driven surge in cyber activity, with weekly attacks per organization rising in Mexico, Canada, and the United States in April, across the media, hospitality, transportation and travel sectors. FIFA-themed domains reached 9,741 in April, and by early May, one in 41 were malicious. Researchers attributed a months-long intrusion against an Azerbaijani oil and gas company to the Chinese-linked FamousSparrow group. Attackers exploited an unpatched Microsoft Exchange server to deploy web shells, then alternated between Deed RAT and TernDoor across three waves of persistent activity.
research.checkpoint.comMay 18, 2026extracted
Western governments lay the groundwork for secure 6G networks
Western governments lay the groundwork for secure 6G networks Governments are preparing for 6G, the next generation of mobile networks, placing security and resilience among their top priorities. In response, seven countries participating in the Global Coalition on Telecoms (GCOT) have introduced a set of 6G Security and Resilience Principles, developed with support from industry partners. The coalition brings together the governments of the United Kingdom, the United States, Canada, Japan, and Australia. Sweden and Finland recently joined as new members. Industry partners supporting the initiative include companies such as Ericsson, Nokia, Samsung, Qualcomm, NEC, AT&T, Vodafone, and NVIDIA. The Principles outline what GCOT governments expect from industry on the security and resilience of next-generation networks. They call for 6G systems protected from cyber and physical threats, supported by resilient supply chains, and able to provide reliable service. A UK Government statement said that “the governments of the GCOT hope that these Principles will serve as a touchstone for future work to develop 6G standards and will inform industry’s 6G research and development. They build on existing GCOT publications, including those on AI and Open RAN certification.” The Principles set out objectives for 6G development and may evolve as technologies and markets develop. “Although the commercial launch of 6G networks is still several years away, it is important to establish early the principles that will guide its development and support its success. The principles have been informed by industry input, and we are pleased to have been part of this process,” said Rob Joyce, Director of Mobile Access Engineering at Virgin Media O2.
helpnetsecurity.comMar 6, 2026extracted
Coalition of Western Countries Launches 6G Cybersecurity Guidelines
A coalition of seven governments has launched a set of voluntary cybersecurity and cyber resilience principles for 6G, the next generation of mobile networks. The Global Coalition on Telecoms (GCOT) was established in October 2023 to set out a shared commitment to support secure, resilient and innovative telecommunication networks. Founded by Australia, Canada, Japan, the UK and the US, the group was joined by Finland and Sweden during Mobile World Congress 2026. At the event in Barcelona, GCOT also launched the 6G Security and Resilience Principles with the support of leading industry partners, including AT&T, BT, Ericsson, NVIDIA, Nokia, Qualcomm, Rakuten Mobile, Samsung Electronics and Virgin Media O2 and Vodafone. While 6G standardization works are still in their infancy, with key industry groups targeting initial commercial rollouts in 2029-2030, GCOT believe broad predictions can be made based on the IMT-2030 Framework and initial 3GPP 6G studies. For instance, the coalition assessed that 6G will mean that more network functions will be virtualized, that disaggregated architectures and standardized interfaces will enable better visibility for security and better multi-vendor integration and that AI will be supported natively both to improve network performance and enable new user services. GCOT has developed four security principles and four resilience principles based on these predictions in order to help build 6G standards, covering resilience to cyber and physical attacks, supply chains, and reliability. The guidelines are also intended as a guide for all relevant stakeholders, according to a statement published by the UK government on March 3. Rob Joyce, director of mobile access engineering at Virgin Media O2, commented: “Although the commercial launch of 6G networks is some years away, it is helpful to establish at an early stage the principles that will guide the development of 6G and ensure its success.” GCOT’s Security and Resilience Objectives for 6G Networks The GCOT 6G guidelines aim to point to some of the critical security and resilience considerations that the coalition member states and industry partners recommend prioritizing in the ongoing development of the 6G system. These include: Containment: the 6G system should limit the ability of malicious actors or software to propagate through the network Confidentiality: the 6G system should be built by design to protect the privacy of user data and able to process and provide data confidentially (e.g. it is secure against eavesdropping or attackers, even for data shared over channels which are not physically secure or known) Integrity: the 6G system should maintain the integrity of data providing guarantees that any changes to data, as it travels through the network, are perceptible, as well as assure the integrity of network infrastructure itself Resilience: the 6G system should be measurably resilient and able to maintain service availability for users even in challenging circumstance, in particular for requirements like emergency or first-responder voice and data services, which must be future proofed in the transition to 6G Regulatory compliance: the operators of 6G systems should be able to fulfil the requirements of relevant national regulations and legislation GCOT further emphasized that future 6G infrastructure should incorporate robust failover mechanisms to ensure uninterrupted connectivity during disruptions. It also highlighted the importance of integrating complementary and alternative positioning, navigation and timing (PNT) solutions beyond GNSS to minimize vulnerability to signal loss or interference. Finally, GCOT advocated for the adoption of Open RAN frameworks and guiding principles to support flexibility, interoperability, and innovation within the network ecosystem. “The technological innovation anticipated from 6G, twinned with its central role in national infrastructure (as with current mobile networks), will require fundamental protections and mitigations to be considered from the outset,” reads the GCOT announcement shared by the UK government. “That will require action on the part of governments, telecommunications providers and those supplying the systems they rely on, including cloud and data infrastructure. It will also mean close working with domestic and regional regulatory bodies and through public-private partnerships, where appropriate, to ensure common understanding of threats and robust compliance.” Ronnie Vasishta, senior VP of telecom at NVIDIA, welcomed the initiative and said his company is “building the AI-RAN platforms that translate these guiding principles into operational reality in software-defined, AI-native 6G networks.” Eva Fogelström, head of security research at Ericsson, said: “We look forward to working with all partners involved in GCOT to ensure the next phase of advanced connectivity is not only high-performing and resilient, but also inclusive, sustainable, and future-ready.”
infosecurity-magazine.comMar 4, 2026extracted
Reddit Hit With $20 Million UK Data Privacy Fine Over Child Safety Failings
Britain’s data privacy watchdog slapped online forum Reddit on Tuesday with a fine worth nearly $20 million for failures involving children’s personal information. The Information Commissioner’s Office said it issued the penalty worth 14.5 million pounds ($19.5 million) because the failures resulted in the platform using children’s data “unlawfully.” “Children under 13 had their personal information collected and used in ways they could not understand, consent to or control. That left them potentially exposed to content they should not have seen,” said Information Commissioner John Edwards. “This is unacceptable and has resulted in today’s fine.” The U.K. privacy regulator has been escalating scrutiny of online platforms over child safety. Earlier this month it hit MediaLab, owner of image-sharing site Imgur, with a 247,590 pound fine over similar failures and it has also been investigating TikTok since last year. The watchdog took issue with Reddit’s age verification measures. It said that even though the platform doesn’t allow children under 13 to use its service, it didn’t have any way to check the ages of its users before July 2025. Edwards said online platforms that are likely to be accessed by children are responsible for protecting them by making sure they’re not exposed to any risks “through the way their data is used.” They can do this with “effective age assurance measures,” he said. Reddit rolled out age verification measures in July 2025 in order for users to access mature content, including asking them to declare their age when setting up an account. But the watchdog said “self-declaration” is easy to bypass and that it told Reddit it would continue to monitor the platform’s handling of children’s data. Reddit said it would appeal the decision. “Reddit doesn’t require users to share information about their identities, regardless of age, because we are deeply committed to their privacy and safety,” the company said in a statement. “The ICO’s insistence that we collect more private information on every UK user is counterintuitive and at odds with our strong belief in our users’ online privacy and safety.” Related: Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches Related: Vodafone Germany Fined $51 Million Over Privacy, Security Failures
securityweek.comFeb 25, 2026extracted
Ad tech firm Optimizely confirms data breach after vishing attack
New York-based ad tech company Optimizely has notified an undisclosed number of customers of a data breach after threat actors compromised some of its systems in a voice phishing attack. Optimizely has nearly 1,500 employees across 21 global offices, and its customer list includes over 10,000 businesses, including high-profile brands like H&M, PayPal, Zoom, Toyota, Vodafone, Shell, Salesforce, and Nike. In breach notification letters sent to affected customers, the company, the threat actors reached out on February 11, claiming they had access to its systems. Optimizely also told BleepingComputer that the attackers breached some of its systems and stole what it described as "basic business contact information." "The threat actor gained access to Optimizely's systems through a sophisticated voice-phishing attack, but was unable to escalate privileges, install software, or create any backdoors in the Optimizely environment, and we have no evidence that the threat actor was able to access sensitive customer data or personal information beyond basic business contact information," it said. Optimizely also noted the "incident was confined to certain internal business systems, records in our CRM, and a limited set of internal documents used for back-office operations," and added that its "business operations continue without disruption." The company also warned customers to be wary of attacks that could use some of the stolen data in further phishing attempts, which may use calls, texts, or emails to ask for passwords, MFA codes, or other credentials. ShinyHunters links While Optimizely didn't share how many customers had their information exposed in the data breach and has yet to name the threat actor behind the attack, it told affected customers that "the communication we received is consistent with the behavior of a loosely affiliated group who use sophisticated and aggressive social engineering tactics, most often involving voice phishing, to attempt to access their victims systems." This hints that the attackers are likely part of the ShinyHunters extortion operation, which has claimed similar breaches at Canada Goose, Panera Bread, Betterment, SoundCloud, PornHub, fintech firm Figure, and online dating giant Match Group (which owns multiple popular dating services, including Tinder, Hinge, Meetic, Match.com, and OkCupid) in recent weeks. While not all of these breaches are part of the same campaign, some victims had their systems compromised in a voice phishing (vishing) campaign targeting single sign-on (SSO) accounts at Microsoft, Okta, and Google across over 100 high-profile organizations. In these attacks, threat actors impersonate targets' IT support, call employees, and trick them into entering credentials and multi-factor authentication (MFA) codes on phishing sites mimicking their companies' login portals. As BleepingComputer first reported, the threat actors have also recently altered their social engineering attacks to use device code vishing, abusing the legitimate OAuth 2.0 device authorization grant flow to obtain Microsoft Entra authentication tokens. Once in, they hijack the victim's SSO account and gain access to connected enterprise services, including Salesforce, Microsoft 365, Google Workspace, Zendesk, Dropbox, SAP, Slack, Adobe, Atlassian, and many others. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comFeb 23, 2026extracted
UK Executives Warn They May Not Survive a Major Cyber-Attack, Vodafone Survey Finds
Major cybersecurity breaches at UK retailers and carmakers last year have raised boardroom awareness of online threats, but many senior executives warn they may go out of business if hit by similar incidents. Vodafone Business polled 1000 senior leaders across businesses of all sizes to better understand their attitudes to cyber risk. Some 89% claimed that big-name breaches at M&S, Jaguar Land Rover (JLR) and other firms last year made them more alert to the potential impact of cyber threats. Yet a worrying 10% admitted their organization would likely not survive a similar incident. The ransomware attacks on M&S and the Co-op Group are estimated to have cost up to £440m. In fact, M&S alone may be on the hook for over £300m in losses after its online operations were knocked out for several months. A lengthy outage at JLR cost the UK economy an estimated £1.9bn, making it the most expensive attack of its kind ever recorded. The Vodafone Business poll chimes with a new Business Resilience Index released on January 22 by MSP Six Degrees. It categorized over a quarter (28%) of UK organizations as “at risk” – with average uptime across critical business services over the past year just 73%. Responses to the Vodafone Business poll revealed that many organizations are still poorly prepared for a serious incident. It found that, on average, staff use their work passwords for up to 11 other personal accounts, including social media and dating sites. This puts them at risk of credential stuffing, where threat actors use automated tooling to try breached passwords across other accounts that share the same credential. Less than half (45%) confirmed that staff have undergone basic cyber-awareness training. AI threats are making the job of corporate cybersecurity teams even harder. Around 70% of business leaders told Vodafone that deepfakes have made them more wary of video involving senior colleagues or their boss. Policymakers Take Note Nick Gliddon, business director at VodafoneThree, described the findings of the research as “alarming,” but claimed that many security best practices such as avoiding password reuse and enhancing staff training “are relatively simple to implement.” The UK government also appears to be getting the message. A second Fraud Sector Charter for telecommunications was signed by the UK’s major telcos in November and will come into force later this year. Among other things it will force the industry to: Upgrade network infrastructure to eliminate number spoofing Introduce a “traceback” solution to help track the origin of suspicious calls in real time Restore trust in SMS messages by introducing sender ID verification, and stricter vetting of businesses using bulk SMS services Improve threat sharing for AI-generated fraud like deepfake voice cloning Enhance victim support “The government’s announcement of its second Fraud Sector Charter for telecommunications, coupled with a new fraud strategy to be launched next year, marks a significant and timely development,” said Gliddon. “This renewed focus from policymakers underscores the seriousness of the threat and the necessity of a united approach between industry and government to effectively tackle online fraud and cybercrime.”
infosecurity-magazine.comJan 22, 2026extracted
CMMC Live: Pentagon Demands Verified Cybersecurity From Contractors
The US Department of Defense’s long-anticipated Cybersecurity Maturity Model Certification (CMMC) program officially entered its enforcement phase on November 10, 2025. Introduced as an amendment to the Defense Federal Acquisition Regulation Supplement (DFARS), the CMMC program requires defense contractors and subcontractors to implement specific cybersecurity measures to protect sensitive information. The Department of Defense, also referred to as the Department of War, can now mandate CMMC compliance as a condition for new defense industrial base (DIB) contracts. The goal is to ensure that contractors and subcontractors can protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). FCI is information not intended for public release that is provided to or generated by a contractor. CUI is sensitive government information that is not classified but still requires protection from unauthorized disclosures. For the past eight years, contractors have been allowed to self-attest to cybersecurity compliance, but now some organizations will also need to undergo a formal assessment by a certified third-party assessor organization (C3PAO). Depending on the sensitivity of the information they handle, contractors must comply with one of three CMMC maturity levels. Level 1, which covers basic safeguarding of FCI, requires an annual self-assessment and compliance with 15 requirements. Level 2, which covers broad protection of CUI, may require a self-assessment or an assessment conducted by a C3PAO to ensure compliance with 110 requirements specified in the NIST SP 800-171 cybersecurity framework. Level 3 is for higher protection of CUI against advanced persistent threats (APTs). It requires an assessment by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) every three years, and compliance with the 110 requirements from NIST SP 800-171 and an additional 24 requirements from NIST SP 800-172 (enhanced security requirements). November 10, 2025, marks the start of the first phase of CMMC implementation, with contractors being required to complete Level 1 and Level 2 self-assessments. In the second phase, which is set to start on November 10, 2026, contractors will be required to complete third-party assessments for Level 2 certifications for new contracts. The third phase is scheduled for November 10, 2027, and it will introduce Level 3 requirements. The fourth and final phase is set for November 10, 2028, and involves full implementation of CMMC requirements across all applicable contracts. While Level 1 and Level 2 include self-assessments, contractors expose themselves to significant risks if they get caught misrepresenting compliance. It’s not uncommon for defense contractors to pay millions of dollars over their cybersecurity failures. The list includes MORSE, Aerojet Rocketdyne, and Raytheon/Nightwing. “This is a GDPR-level event,” said Shrav Mehta, CEO of Secureframe, a company that offers CMMC compliance services and which published guidance this week. “Many defense contractors are still using personal emails or commercial solutions that don’t meet the bar for storing classified information — often manufacturing companies without IT departments,” Mehta explained. “That’s where the real vulnerability is: not with the big prime contractors, but with the subcontractors who don’t have the resources or expertise to secure this data alone.” A report published in late September by DOD cybersecurity compliance services provider CyberSheath showed that only 1% of defense contractors had felt fully prepared for CMMC, a decrease from 4% in 2024. “Eighty thousand defense contractors need Level 2 certification, yet only 270 of these organizations currently hold final CMMC certificates,” Emil Sayegh, CEO of CyberSheath, said at the time. “The math is simple and alarming. Contractors that aren’t prepared will be locked out of billions in DOD contracts while their competitors who invested in real compliance and cybersecurity capture the business.” In response to the CMMC enforcement, cybersecurity companies have launched new products and updated existing platforms to aid companies with becoming compliant. CMMC compliance offerings were announced in recent days by AWS and Wiz (partnership), Huntress, Strike Graph, USX Cyber, and Sensiba. Related: Former US Defense Contractor Executive Admits to Selling Exploits to Russia Related: SafeHill Emerges from Stealth With $2.6 Million Pre-Seed Funding Related: Vodafone Germany Fined $51 Million Over Privacy, Security Failures
securityweek.comNov 11, 2025extracted
UK carriers to block spoofed phone numbers in fraud crackdown
Under a new partnership with the government aimed at combating fraud, Britain's largest mobile carriers have committed to upgrading their networks to eliminate scammers' ability to spoof phone numbers within a year. This agreement is part of the new Telecoms Charter, which brings together law enforcement, government agencies, and Britain's top mobile networks, including BT EE, Virgin Media O2, Vodafone Three, Tesco Mobile, TalkTalk, and Sky. It requires carriers to upgrade their networks to indicate when calls originate from abroad, preventing fraudsters from impersonating banks, government agencies, and other trusted organizations. "Advanced call tracing technology will also be rolled out across mobile networks to give police the intelligence to track down scammers operating across the country and dismantle their operations," the UK Home Office said in a Wednesday press release. "New commitments to boost data sharing with the police will shine a light on the mobile networks that let scam calls slip through the net, empowering customers and making it harder for scams to go undetected." The signatories have also committed to improving support for scam victims, reducing response times to two weeks, and establishing measurable goals for prompt fraud assistance. Murray Mackenzie (director of fraud prevention at Virgin Media O2) said the company has already blocked over 1 billion scam texts and flags 50 million suspicious calls monthly using AI, while Rachel Andrews (corporate security and fraud director at Vodafone Three) reported blocking millions of fraudulent calls and scam texts daily. According to data shared by the UK government today, 96% of mobile users check caller ID before answering, with three-quarters blocking calls from unknown international numbers, a trend exploited by scammers who spoof UK numbers to appear local and trustworthy. "Spoofed calls allow scammers to deceive the public with fake identities and false promises. In a major upgrade of our mobile network, call spoofing will be eliminated within a year - stripping away the tools scammers use to cheat people out of their hard-earned cash," said Minister for Fraud Lord Hanson. "We're stepping up our defences to protect victims and make sure the UK is the hardest place in the world for scammers to operate." Deputy Commissioner Nik Adams of the City of London Police also welcomed today's announcement, noting that fraud accounts for 50% of all crime in the United Kingdom. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comNov 5, 2025extracted
Fastweb+Vodafone e 7Layers, DefenderAI: il SOC virtuale AI-driven che porta la cyber security Enterprise nelle PMI
Le piccole e medie imprese italiane sono oggi tra i target preferiti dei cyber criminali. Nel mirino finiscono soprattutto realtà con risorse limitate, prive di team interni dedicati e con infrastrutture non sempre aggiornate. La diffusione del ransomware-as-a-service, le campagne di phishing sempre più sofisticate e l’aumento degli attacchi alla supply chain hanno reso evidente quanto il tessuto produttivo sia esposto a rischi crescenti. In questo scenario, la carenza di competenze cyber – uno skill gap confermato da più ricerche e sottolineato anche dalle analisi pubblicate su Cybersecurity360 – costituisce un freno ulteriore. Le PMI non dispongono delle capacità né economiche né umane per allestire un Security Operation Center (SOC) tradizionale, con analisti dedicati h24 e infrastrutture di detection & response complesse. Da qui nasce la necessità di soluzioni innovative, capaci di portare protezioni tipicamente Enterprise anche in contesti di dimensioni ridotte. È in questo contesto che si colloca DefenderAI, la piattaforma nata e sviluppata dalla collaborazione fra Fastweb+Vodafone e 7Layers, finalista ai Cybersecurity360 Awards. Una suite modulare che integra protezione di rete, EDR, vulnerability scanning, filtro contenuti e percorsi di cyber awareness, orchestrati in un’unica dashboard. Il tutto supportato da un SOC virtuale AI-driven, in grado di replicare il lavoro di un analista umano sfruttando machine learning e intelligenza artificiale generativa. Indice degli argomenti Le PMI italiane si trovano a gestire rischi crescenti con strumenti spesso frammentati. Molte aziende hanno firewall tradizionali e soluzioni antivirus, ma raramente dispongono di sistemi avanzati di detection o di personale in grado di analizzare log e correlare eventi di sicurezza. Le normative europee, dalla NIS2 al DORA, alzano l’asticella: la resilienza operativa, la capacità di monitoraggio continuo e la risposta tempestiva agli incidenti non sono più opzionali, ma requisiti di legge. Tuttavia, per una PMI, costruire un SOC interno è proibitivo: servono budget importanti, figure altamente specializzate e infrastrutture dedicate. È proprio per colmare questo gap che nasce DefenderAI, con l’obiettivo di fornire un approccio “chiavi in mano” che riduca al minimo la complessità gestionale e permetta di elevare il livello di sicurezza. La soluzione è progettata per essere cloud-native, con provisioning rapido e scalabile. Dal punto di vista tecnologico, DefenderAI integra: firewall e sistemi IPS nel backbone Fastweb per la protezione perimetrale; EDR per il monitoraggio e la risposta sugli endpoint, con rilevamento di minacce avanzate e comportamenti anomali; vulnerability assessment tramite motore OSINT, con analisi da fonti pubbliche, deep e dark web; piattaforma di cyber awareness con video, test e gamification, per ridurre il rischio umano; framework MITRE ATT&CK per la classificazione tecnica delle minacce rilevate. La gestione avviene tramite una dashboard centralizzata, che fornisce una visione olistica: provenienza geografica degli attacchi, tipologia e severità degli incidenti, trend delle vulnerabilità e insight per decision maker anche non tecnici. Uno degli aspetti più innovativi del progetto è il SOC virtuale AI-driven. Un analista virtuale che attraverso l’intelligenza artificiale accelera il triage, automatizza la correlazione degli eventi e produce report immediatamente utilizzabili. Per una PMI significa ridurre drasticamente i tempi di detection e risposta, senza dover sostenere i costi di un SOC interno. Dal punto di vista tecnico, questo approccio presenta vantaggi evidenti: riduzione dei falsi positivi grazie al machine learning addestrato su casi reali; rapidità nell’identificazione delle minacce, con automazione dei processi di indagine; scalabilità cloud, che rende la soluzione accessibile anche a organizzazioni con poche decine di dipendenti. Restano tuttavia alcune sfide: l’AI non elimina la necessità di supervisione umana in scenari complessi e la maturità delle PMI nel gestire le informazioni di sicurezza può essere un limite iniziale. Per questo la componente di reporting semantico e di awareness diventa cruciale: semplifica la comprensione e supporta un percorso di crescita culturale oltre che tecnologica. I clienti che hanno adottato DefenderAI hanno ottenuto benefici misurabili su tre livelli: tecnologico: protezione attiva e reattiva senza dover costruire un SOC interno, riduzione dei falsi positivi, maggiore efficacia di detection; operativo: tempi di triage e risposta ridotti, insight immediati e indicazioni guidate anche per personale non esperto; formativo: aumento della consapevolezza e riduzione del rischio umano grazie a programmi di formazione continua. DefenderAI si distingue anche per la sua replicabilità: il servizio cloud è già attivo in decine di realtà italiane e può essere esteso facilmente grazie alla modularità. Le aziende possono iniziare dal pacchetto Entry e crescere progressivamente, senza investimenti upfront. Dal punto di vista dell’innovazione, l’uso combinato di machine learning e GenAI in un SOC virtuale rappresenta un approccio originale, capace di unire analisi avanzata e semplicità di fruizione. La dashboard unica, progettata per decision maker anche non tecnici, e l’integrazione di funzionalità di awareness fanno di DefenderAI una soluzione pensata specificamente per il mercato delle PMI. Con DefenderAI mettiamo a disposizione delle piccole e medie aziende uno strumento per la difesa contro le minacce informatiche tra i più avanzati grazie all’integrazione dell’AI con le nostre infrastrutture di rete e le soluzioni di cybersecurity”, afferma il team di sviluppo integrato Fastweb+Vodafone e 7Layers. Una frase che riassume bene l’obiettivo del progetto: democratizzare la cyber security, portando livelli di protezione enterprise in contesti finora penalizzati da costi e complessità. In definitiva, DefenderAI si propone come un modello concreto di come sia possibile ridurre il divario tra grandi organizzazioni e PMI in ambito cyber. Per i CISO e i responsabili IT, rappresenta un’opzione per rafforzare la postura di sicurezza senza appesantire le strutture interne. “Il fatto che DefenderAI sia tra i finalisti dei Cybersecurity360 Awards conferma la rilevanza di un approccio che unisce innovazione tecnologica, automazione intelligente e attenzione alla realtà operativa del tessuto imprenditoriale italiano” afferma Riccardo Baldanzi, COO di 7Layers.
cybersecurity360.itSep 18, 2025extracted
Maximulta a Vodafone e al responsabile trattamento dati: ecco i 3 errori da evitare
Questa volta a sanzionare è il Garante greco che rende noto di aver sanzionato in maniera esemplare Vodafone con una multa pari a euro 550mila: 350mila euro per violazione dell’art. 28 più 200 mila euro per violazione di uno dei principi cardini del GDPR di accuratezza, e 40mila euro al suo responsabile del trattamento l’affiliato Ds Phone per aver violato a sua volta il GDPR. Ecco perché l’Autorità Garante greca ha comminato la maximulta a Vodafone e al suo responsabile del trattamento dati. Indice degli argomenti Un abbonato/utente Vodafone si è rivolto all’Autorità Garante privacy greca, in quanto lì si trovava ai tempi dell’accaduto, quando ha subìto una registrazione illegale di più connessioni mobili (oltre 15) prepagate a suo nome, patendo quindi un furto di identità. Nella vicenda tuttavia entra in gioco anche un’altra società in franchising affiliata Vodafone, DS Phone, che effettuava materialmente l’errata identificazione che poi ha generato la violazione dei dati, senza nemmeno rilevarla. Il trattamento illecito dei dati ha avuto conseguenze sia a carico di Vodafone, quale titolare del trattamento, che a carico di DS Phone, come responsabile del trattamento. Quest’ultimo si è difeso sostenendo che, nel caso di specie “l’intenzione era quella di registrare quei 15 numeri sotto l’identità di un accompagnatore turistico di gruppo, e che, per errore, una copia della carta d’identità del denunciante – memorizzata nel sistema di un negozio partner a cui la società aveva accesso – era allegata alla domanda”. Successivamente, i dati personali della persona che ha denunciato erano risultati collegati a tali abbonamenti. La indicavano come proprietaria, “sebbene non fosse mai stata in possesso delle loro schede SIM”. Vodafone per parte sua smentisce, cercando di distanziarsi dalla pratica contestata di “scambio di documenti (di identità) tra partner” dicendo che la stessa non solo non è contemplata nelle procedure di Vodafone, ma in palese violazione delle stesse. In ogni caso, provvedeva a segnalare il data breach all’Autorità garante greca secondo i crismi dettati dall’art. 33. Il cuore della decisione lo si ricava dall’estratto sintetico che riportiamo tal quale ove si legge infatti che “nell’ambito dell’audit amministrativo condotto dall’Autorità è emerso che il responsabile del trattamento ha agito in violazione delle istruzioni di Vodafone, in qualità di titolare del trattamento, e non ha seguito la procedura di identificazione dell’abbonato nel punto vendita. […] Allo stesso tempo, è stata riscontrata anche una violazione da parte di Vodafone, in qualità di titolare del trattamento, in merito ai suoi obblighi di attuare misure tecniche e organizzative adeguate, di selezionare idonei responsabili del trattamento e di controllarli in modo efficace, nonché una violazione del principio di accuratezza dei dati”. Dal provvedimento, ecco che emergono almeno tre errori da evitare e che speriamo facciano scuola, traendo spunto da questo caso: scegliere responsabili del trattamento non idonei né adeguati; non vigilare efficacemente sull’operato del responsabile; non fare la DPIA, e avere misure di sicurezza insufficienti e inefficaci. Innanzitutto, è fondamentale scegliere bene i propri fornitori che agiscono in qualità di responsabili da trattamento da formalizzare ex art. 28 Gdpr nelle preferibili forme di cui alle SCC. La sottoscrizione di un contratto o altro atto giuridico ben fatto nel senso di conforme non rappresenta soltanto una mera formalità, ma è un requisito sostanziale di legge (art. 28, par. 3). Nel caso specifico, si legge nel provvedimento, “non era stato concluso alcun contratto appropriato con il responsabile del trattamento ai sensi dell’art. 28, par. 3 GDPR”. Ora è interessante notare come il termine ’“appropriato” faccia venire a mente quella idoneità del fornitore/responsabile chiamato ad avere sufficienti garanzie, per rivestire il ruolo da responsabile. Garanzie che nel caso di specie si sono rivelate, stando alla lettura degli atti, totalmente inadeguate dal momento che il fornitore in questione non era stato neppure in grado di rilevare il data breach. Oltre al fatto che il titolare deve avvalersi “solo di responsabili del trattamento che forniscano garanzie sufficienti per l’attuazione di misure tecniche e organizzative adeguate”, è chiamato altresì ad “esercitare un’efficace vigilanza attraverso controlli e ispezioni nei punti vendita del responsabile del trattamento”. In altri termini, al titolare è richiesto un attento controllo sull’operato del responsabile, con frequenti audit (concordanti), non bastando semplicemente nominarlo, fornirgli le istruzioni sulla carta e lasciarlo operare senza alcuna verifica, a campione. Infine, l’importanza della valutazione di impatto (art. 35) il cui adempimento non solo va fatto, ma va anche verificato nelle sue risultanze. Dalla lettura del provvedimento abbiamo tratto che, nel caso di specie, Vodafone non aveva fatto la valutazione di impatto, se non dopo l’avvio dell’istruttoria da parte dell’Autorità garante greca, leggendo nel testo “fino al momento in cui si è verificato l’incidente, le misure adottate sia per identificare i clienti sia per evitare il riutilizzo dei loro documenti erano incomplete”. Non solo, “lo studio sulla valutazione d’impatto sulla protezione dei dati (DPIA) non sembra aver considerato il rischio di un’assegnazione di massa di numeri da parte di partner malintenzionati o terzi”, con la ovvia conseguenza di avere misure di sicurezza del tutto insufficienti. Mentre le misure di sicurezza devono essere sufficienti ed efficaci cioè realmente forti, idonee a prevenire incidenti di sicurezza in futuro.
cybersecurity360.itSep 11, 2025extracted