Hackers breach Nokia developer community
SQL injection attack forces Nokia to take down a developer community forum.
Nokia's developer website has been hit by an SQL injection attack.
The Finnish mobile firm warned a significant number of members from the mobile giant's developer community forum had their details accessed.
The site has been taken down as a precautionary measure. The vulnerability exploited to attack the forum has been addressed, Nokia confirmed.
What we think...
Nokia has added to the growing list of tech giants who have been hit by a hack attack this year.
Sony and RSA have already felt the pain of what a data breach means in terms of cost and reputation. Nokia, already in a bedraggled state in the smartphone market, will be hoping the ramifications aren't so serious.
Tom Brewster, Senior Staff Writer
"During our ongoing investigation of the incident we have discovered that a database table containing developer forum members' email addresses has been accessed, by exploiting a vulnerability in the bulletin board software that allowed an SQL Injection attack," a post on the developer.nokia.com/community discussion forum read at the time of publication.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Initially we believed that only a small number of these forum member records had been accessed, but further investigation has identified that the number is significantly larger."
As for what data could have been swiped by the intruders, Nokia said email addresses were compromised. For a small proportion of users who chose to include such information in their public profile, birth dates and usernames for Web 2.0 sites including MSN, Skype and Yahoo were accessed.
"They do not contain sensitive information such as passwords or credit card details and so we do not believe the security of forum members' accounts is at risk. Other Nokia accounts are not affected," Nokia added.
"We are not aware of any misuse of the accessed data, but we are communicating with affected forum members, though we believe the only potential impact to them may be unsolicited email. Nokia apologises for this incident."
Tom Brewster is currently an associate editor at Forbes and an award-winning journalist who covers cyber security, surveillance, and privacy. Starting his career at ITPro as a staff writer and working up to a senior staff writer role, Tom has been covering the tech industry for more than ten years and is considered one of the leading journalists in his specialism.
He is a proud alum of the University of Sheffield where he secured an undergraduate degree in English Literature before undertaking a certification from General Assembly in web development.
-
Manufacturers report millions in losses as downtime wreaks havoc on operationsNews UK manufacturers are losing up to £736 million every week due to downtime, according to new research, with outages lasting for several days on end.
-
Microsoft gives OpenAI restructuring plans the green lightNews The deal removes fundraising constraints and modifies Microsoft's rights to use OpenAI models and products
-
Nokia waves off IntelBroker breach claims, says leaked source code came from a third party applicationNews Notorious threat actor IntelBroker released a cache of stolen data
-
Nokia subsidiary reveals data breach following Conti ransomware raidNews SAC Wireless notifies current and former employees that their personal information may be at risk
-
Nokia blackmailed for millions of Euros six years agoNews Criminals who stole source code extorted phone company, according to reports
-
Week in Review: Kaspersky hit by hackers, UK hit by spending cutsNews This week, security company Kaspersky gets hit by an anti-virus scam and George Osborne unleashes the spending cuts on the nation.
-
Week in Review: Nokia World and the invisible keyboardNews This week in IT, Nokia World was held in London, HP spent over a billion on a security firm and an invisible keyboard was created.
-
Smartphone security survives hacking tournamentNews Smartphones are left unhacked, but is that because they are inherently secure, or because security experts don’t know enough about them?
-
Check Point buys up Nokia’s security appliancesNews A 12-year collaborative effort ends with Check Point taking over Nokia’s portfolio and making it its own.
-
Week in Review: Apple confuses on securityNews This week, Apple's attitude to security confuses, as does the drive to make mobile phones work on underground trains.
