CyberX9 says data of 20 mn postpaid customers of Vi exposed; telco denies

Multiple vulnerabilities in the system of telecom operator Vodafone Idea has exposed the call data records of around 20 million postpaid customers, cyber security research firm CyberX9 said

Vodafone Idea
Vodafone Idea
Press Trust of India New Delhi
3 min read Last Updated : Aug 29 2022 | 12:19 AM IST

Multiple vulnerabilities in the system of telecom operator Vodafone Idea has exposed the call data records of around 20 million postpaid customers, cyber security research firm CyberX9 said in a report.

Vodafone Idea (Vi), however, said there was no data breach and potential vulnerability in its billing communication was immediately fixed after it learned about it.

According to the CyberX9 report, the vulnerability exposed postpaid customers' call data records, comprising the time when a call was made, duration of call, location from which the call was made, customer's full name and address, SMS details comprising contact number to which it was sent, among others.

CyberX9 founder and Managing Director Himanshu Pathak told PTI that the firm had shared entire findings with Vodafone Idea through email and a company official had acknowledged the vulnerability on August 24.

Pathak said CyberX9 reported details to Vi on August 22.

"Later on August 22, 2022, Vi confirmed the receipt of our report. Vodafone Idea acknowledged the vulnerabilities discovered and reported by us on August 24, 2022," Pathak said.

When contacted, Vodafone Idea said, "There is no data breach as alleged in the report. The report is false and malicious. Vi has a robust IT security framework to keep our customer data safe."

"We regularly conduct checks and audits to further strengthen our security framework. We learnt about a potential vulnerability in billing communication. This was immediately fixed and a thorough forensic analysis was conducted to ascertain no data breach," it said.

The company further said that it has notified about the potential vulnerability to appropriate agencies and made due disclosures, adding, "Vi customer data remains fully safe and secure."

The company has also made disclosure of the vulnerability on its website.

However, CyberX9 has contested the claim.

"Vi was exposing millions of customers call logs and other sensitive data for at least last about two years. In that massive time period, multiple criminal hackers might have stolen this data.

"It is absurd and baseless claim of Vi that they've done a forensic audit and no breach was found. Such a detailed forensic audit would at least take couple of months to be done," CyberX9 said.

The CyberX9 report claimed that data of around 301 million people was exposed due to this vulnerability.

CyberX9 found that call data records of 20.6 million Vi postpaid customers was exposed. This comprised personal data, call records, SMS records, internet usage records and roaming details.

The cyber security firm claimed that personal data of 55 million people, including those who have left Vi and those who only showed interest in getting a Vi connection, was at risk.

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

Subscribe to Business Standard digital and get complimentary access to The New York Times

Quarterly Starter

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

Save 46%

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Access to Exclusive Premium Stories Online

  • Over 30 behind the paywall stories daily, handpicked by our editors for subscribers

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :Vodafone Ideatelecom sector

First Published: Aug 28 2022 | 6:01 PM IST

Next Story