ETSI says attackers stole its online user database

Organization
European Telecommunications Standards Institute (ETSI)
Exploit
Hacking
Industry
Standards Body

The European Telecommunications Standards Institute disclosed on September 27, 2023 that it had been the target of a cyberattack and believed the database listing its online users had been exfiltrated. ETSI is a not-for-profit standards development organization based in Sophia Antipolis, France, whose specifications underpin GSM, 3G, 4G and 5G, and it counts more than 900 member organizations across roughly 60 countries.

Attackers exploited a vulnerability in the IT portal that members use for technical work. ETSI did not describe the flaw, state when the intrusion occurred, or say whether the motive appeared to be criminal or espionage. It also did not publish an estimate of how many individual user records were in the stolen database.

France's national cybersecurity agency, ANSSI, worked with ETSI's IT team to investigate and repair the affected systems. Under ANSSI's guidance the institute fixed the vulnerability, took additional security actions and strengthened its IT security procedures. ETSI asked users of its online services to change their passwords.

A judicial inquiry was opened, and ETSI notified France's data protection authority, CNIL, as required under the General Data Protection Regulation. Director-General Luis Jorge Romero framed the episode as a crisis the organization had moved quickly to contain and credited ANSSI's experts with helping determine the remedial actions taken.

Sources