Nokia confirms data breach leaked third-party code, but its data is safe

Cyberattack
(Image credit: Pixabay)

  • Nokia investigation confirms cyberattack with a third party
  • The company says its own data is secure
  • It will continue to monitor the situation

Nokia has confirmed a recent data breach did indeed happen, but did not affect its own internal data.

The telecoms giant said it had completed its initial investigation into the incident, confirming that a breach had occured, but that its systems, and data, is intact.

"Our investigation has found no evidence of any of our systems or data being impacted. Our investigations point to a 3rd party security incident, related to a single customized software application," the company told BleepingComputer.

End of life

An infamous data leaker known as IntelBroker recently posted a new ad on an underground forum, advertising a stolen archive apparently containing data from the telco giant.

The archive was taken from a third party, and was said to contain a large collection of Nokia source code, with the hacker claiming to have stolen Nokia software, SSH keys, RSA keys, BitBucket logins, SMTP accounts, webhooks and hardcoded credentials.

IntelBroker claims to have breached a third-party vendor via a SonarQube server. There, they downloaded sensitive files belonging to multiple companies, including Nokia.

“We have found no evidence that this 3rd party incident would in any way endanger critical Nokia systems or data, including source code, customized software, or encryption keys. Our customers are in no way impacted, including their data and networks,” Nokia added.

The source code IntelBroker leaked was for an application that the third-party built, for a client of Nokia’s. It was supposed to work on only one network, and will not work elsewhere, it was added. No Nokia code was found inside, either.

The company concluded its statement by saying it was “closely monitoring” the situation.

IntelBroker is reportedly a Serbian hacker who has been active since October 2022, and has a history of high-profile attacks. More than 80 separate leaks have been posted to online forums by IntelBroker to date, with targets including companies and organizations such as AMD, Apple, Europol and HPE.

Via BleepingComputer

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
HPE
HPE investigating claims that hacker breached developer environments, source code
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
Telefonica
Telefónica says it was hit by systems breach, internal data leaked online
An abstract image of digital security.
Orange confirms it suffered breach after hacker leaks company documents
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
Third-party data breaches have become a major security concern
Ransomware
Atos now says its systems weren't hit by a ransomware attack after all
Latest in Security
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Marvel Rivals
Marvel Rivals will get two new hero skins for Moon Knight and Black Panther this week meaning I'll now need to farm even more Units