Light Reading
Customer data stolen in security breach that could lead to phishing attacks on subscribers.

Orange France Hacked

Ray Le Maistre
5/8/2014
50%
50%

The personal details of about 1.3 million Orange France customers were stolen by hackers in April, the operator has admitted.

Details including the name, date of birth, fixed and mobile numbers, and email addresses (but not bank details) were stolen in a security breach that was discovered on April 18. The operator has warned that the information stolen could be used in phishing attacks on customers whose details were compromised.

Orange France admitted earlier this year that the personal information of about 800,000 customers was stolen during January.

The data breach highlights the constant struggle that operators face to keep their customers' data secure, a struggle that will be discussed at the upcoming Mobile Network Security Strategies conference in London, which will take place on May 21 at The Thistle Marble Arch hotel.

Patrick Donegan, Heavy Reading senior analyst and mobile network security expert who is hosting the conference, says operators need to consider their levels of investment in security systems, especially as they deploy new networks.

"Information security has always been a strong differentiator for telcos," says Donegan. "In the all-IP networking era, telcos need to increase investment in their own internal security processes as well as their network defenses. It's critical for telcos that their customers understand that they are their most trusted ally in the battle against attacks on private information, no matter who or where they come from."

That trust will come under increasing scrutiny, though, if such breaches become more commonplace. Ironically, Orange only recently conducted a survey which found that consumers are becoming increasingly concerned about the data being stored about them by third-party organizations such as communications service providers, handset manufacturers, and social media networks. (See Euronews: Consumers Freak Out Over Data Security.)

That concern will only increase if operators fail to tell their customers of such security breaches in a timely fashion.

George Anderson, a director at security technology specialist Webroot Software Inc. , is surprised by "the length of time between the attack happening and it becoming public knowledge -- almost three weeks -- especially as the data stolen is ideal for phishing subscribers using email, SMS and phone calls. Most phishing sites are 'live' for just a few hours and the phishing attack is often indistinguishable from genuine communications and requests. That's why it's vital that Orange France customers, the potential victims, are made aware of any threat to them immediately," said Anderson in comments emailed to Light Reading.

Ray Le Maistre, Circle me on Google+ Follow me on TwitterVisit my LinkedIn profile, Editor-in-Chief, Light Reading


Want to learn more about this topic? Check out the agenda for Mobile Network Security Strategies, which will take place on May 21 at The Thistle Marble Arch hotel in London. For more on the event, including the stellar service provider speaker line-up, see the event's official site.


(7)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View
DOShea
50%
50%
DOShea,
User Rank: Blogger
5/11/2014 | 5:08:20 PM
Re: slow reaction time
Breaches like this will hopefull force operators to really tell customers how they protect their data throughout the value chain. Everyone claims high levels of security, and customers don't really know from one carrier to the next the different approaches that are being taken.
MordyK
50%
50%
MordyK,
User Rank: Light Sabre
5/9/2014 | 2:33:31 PM
Re: Value of data
The market bears me out :)
SarahReedy
50%
50%
SarahReedy,
User Rank: Blogger
5/9/2014 | 2:13:49 PM
Re: slow reaction time
I think it requires protective measures at every step of the value chain from the network to the web to end user devices. Right now, there are a lot of holes where things can go wrong.
SarahReedy
50%
50%
SarahReedy,
User Rank: Blogger
5/9/2014 | 2:12:55 PM
Re: Value of data
ha, so cybercriminals are better at big-data analytics than operators? Not too far off...
MordyK
50%
50%
MordyK,
User Rank: Light Sabre
5/8/2014 | 9:33:14 PM
Value of data
The joke is that while carrier's bsaically don't recognise the data's potential, hacker's recognise the locked up value and make attempts to get at it.

The upside of this is that business work on market economics, so attempts at getting this data highlight its potential value opportunity. 
danielcawrey
50%
50%
danielcawrey,
User Rank: Light Sabre
5/8/2014 | 2:29:36 PM
Re: slow reaction time
Phishing and other types of social hacking are becoming a major problem. I am hoping that sometime soon we can come to a consensus on the web for digital identities to thwart this growing problem. 

The issue is that there are almost a byzantine array of solutions being developed. Two-auth is a nice stepping stone, but then you get into biometrics that can open up a host of issues that have never been considered. 
SarahReedy
50%
50%
SarahReedy,
User Rank: Blogger
5/8/2014 | 12:55:07 PM
slow reaction time
Wow, it would seem that time is of the essence in any security breach like this so that customers can take necessary precautions to protect their identities. Is Orange advising them on what to do now, or is it too late?
Flash Poll
LRTV Custom TV
VeEX – Live from the Show

8|21|14   |   5:58   |   (0) comments


An overview of VeEX Test and Measurement solutions including TX300S multi-service test set with VeExpress cloud-based management system, UX400 universal modular platform supporting 100G testing, and the redesigned RXT modular platform.
LRTV Custom TV
Transitioning CE 2.0 Networks Into the SDN & NFV Era With Telco Systems

8|19|14   |   5:19   |   (0) comments


Telco Systems' Ariel Efrati (CEO) and Moshe Shimon (VP of Product Management) discuss virtualization and how the company's new Open Metro Edge solution utilizes the SDN and NFV concepts to accelerate and orchestrate service delivery through its innovative product portfolio and software applications.
LRTV Custom TV
NFV Myths: Is NFV Still Several Years Away?

8|11|14   |   1:13   |   (0) comments


Some say that NFV (network functions virtualization) is still several years away from being implemented on mobile operator networks. This isn't the case. Operators can get started on their paths to NFV now, as this short video from Skyfire shows.
LRTV Custom TV
A New Security Paradigm in SDN/NFV

7|28|14   |   02:54   |   (0) comments


Paul Shaneck, Global Director Network Solutions for Symantec, discusses the evolving virtualized network, explaining how Symantec is leading the security discussion as it relates to SDN and NFV, and helping to ensure the network is protected and compliant.
LRTV Documentaries
Sprint's Network Evolution

7|24|14   |   14:59   |   (0) comments


Sprint's Jay Bluhm gives a keynote speech at the Big Telecom Event (BTE) about Sprint's network and services evolution strategy, including Spark.
LRTV Documentaries
BTE Keynote: The Software-Defined Operator

7|24|14   |   18:43   |   (1) comment


Deutsche Telekom's Axel Clauberg explains the concept of the software-defined operator to the Big Telecom Event (BTE) crowd.
Light Reedy
Numbers Are In: LR's 2014 Salary Survey

7|24|14   |   1:25   |   (7) comments


Our fourth annual Salary Survey paints a picture of who's hiring, firing, earning, and yearning for a change in the telecom industry.
LRTV Custom TV
Driving the Network Transformation

7|23|14   |   4:29   |   (0) comments


Intel's Sandra Rivera discusses network transformation and how Intel technologies, programs, and standards body efforts have helped the industry migration to SDN and NFV.
LRTV Custom TV
Distributed NFV-Based Business Services by RAD

7|18|14   |   5:38   |   (0) comments


With the ETSI-approved Distributed NFV PoC running in the background, RAD's CEO, Dror Bin, talks about why D-NFV makes compelling sense for service providers, and about the dollars and cents RAD is putting behind D-NFV.
LRTV Custom TV
MRV Accelerating Packet Optical Convergence

7|15|14   |   6:06   |   (0) comments


Giving you network insight to make your network smarter.
LRTV Custom TV
NFV-Enabled Ethernet for Generating New Revenues

7|15|14   |   5:49   |   (0) comments


Cyan's Planet Orchestrate allows service providers and their end-customers to activate software-based capabilities such as firewalls and encryption on top of existing Ethernet services in just minutes.
LRTV Custom TV
Symkloud NVF-Ready Video Transcoding, Big Data

7|9|14   |   3:41   |   (0) comments


Kontron and ISV partner Vantrix demonstrate high-performance video transcoding and data analytic solutions on same 2U standard platform that is ready for SDN and NFV deployments made by mobile, cable and cloud operators.
Upcoming Live Events!!
September 16, 2014, Santa Clara, CA
September 16, 2014, Santa Clara, CA
September 23, 2014, Denver, CO
October 29, 2014, New York City
November 6, 2014, Santa Clara
November 11, 2014, Atlanta, GA
December 9-10, 2014, Reykjavik, Iceland
June 9-10, 2015, Chicago, IL
Infographics
Today's Cartoon
Hot Topics
Level 3 Does Big Data Differently
Carol Wilson, Editor-at-large, 8/21/2014
T-Mobile: Small Cells? We're Dense Already
Dan Jones, Mobile Editor, 8/22/2014
Comcast Streams Back to School
Mari Silbey, Independent Technology Editor, 8/21/2014
Sprint Drops Prices, But Also Speeds?
Sarah Reedy, Senior Editor, 8/21/2014
Line-Powered Phone Lines: A Hot Topic Again
Carol Wilson, Editor-at-large, 8/20/2014
Like Us on Facebook
Twitter Feed