Nokia denied breach after IntelBroker leaked contractor source code
- Organization
- Nokia
- Exploit
- Third-Party Data Breach
- Industry
- Telecommunications
On November 4, 2024, the threat actor known as IntelBroker advertised what was described as a large collection of Nokia source code for sale on the BreachForums cybercrime marketplace. The listing claimed the archive held SSH keys, RSA keys, Bitbucket logins, SMTP accounts, webhooks and hardcoded credentials alongside the code, and the actor said the asking price was $20,000.
Nokia opened an investigation and then rejected the framing of the claim. The company said it had found no evidence that its own systems or data were affected, and that the material came from a third party that had been developing a customized application for a single customer network. According to IT Pro, the actor reached the files through that contractor's SonarQube server, which was accessible with default credentials and allowed the download of Python projects belonging to Nokia and other clients. IT Pro also reported the archive contained material relating to the Indian operator Vodafone Idea.
After Nokia's denial, IntelBroker announced on November 7 that the data would be given away rather than sold, and posted it publicly. Nokia did not change its position, maintaining that no Nokia systems were compromised.
The contents of the archive were never independently verified in full, and the scale of the theft rested largely on the attacker's own description.