Sim maker confirms its systems were hacked

Published February 26, 2015
PARIS: Gemalto Chief Executive Officer Olivier Piou arrives to attend a news conference on Wednesday. He announced his company would not pursue legal action against the US and UK agencies which were probably behind hacking of his firm’s systems.—Reuters
PARIS: Gemalto Chief Executive Officer Olivier Piou arrives to attend a news conference on Wednesday. He announced his company would not pursue legal action against the US and UK agencies which were probably behind hacking of his firm’s systems.—Reuters

PARIS: A European maker of Sim (subscriber identity module) cards, Gemalto, said on Wednesday it had suffered hacking attacks that were likely conducted by US and British intelligence agencies but denied any “massive theft” of encryption keys that could be used to spy on mobile phone conversations.

Investigative website The Intercept last week said the US National Security Agency and Britain’s GCHQ hacked into the firm in 2010 and 2011 and stole Sim encryption keys, with which they could reportedly monitor communications over mobile phones without using a warrant or wiretap.

Know more: US, UK hacked into systems of SIM card firm: report

The website made the allegations on the theft of the keys — which encrypt and decrypt data — based on a document leaked by former NSA contractor Edward Snowden, and its report prompted some experts to decry a huge breach in mobile privacy.

“In 2010 and 2011, we detected two particularly sophisticated intrusions which could be related to the operation,” Gemalto said in a statement.

“During the same period, we also detected several attempts to access the PCs of Gemalto employees who had regular contact with customers,” it added.

“At the time we were unable to identify the perpetrators but we now think that they could be related to the NSA and GCHQ operation.”

But the company denied that these attacks resulted in a large-scale theft of encryption keys. “The attacks against Gemalto only breached its office networks and could not have resulted in a massive theft of SIM encryption keys,” it said.

CEO Olivier Piou said the company would not file a complaint against the spy agencies as “the facts are difficult to prove from a legal standpoint and suing a state is long and costly.”

The firm said the aim of the operation was to intercept the encryption keys as they were exchanged between mobile operators and suppliers such as Gemalto.

But “by 2010, Gemalto had already widely deployed a secure transfer system with its customers and only rare exceptions to this scheme could have led to theft”.

Patrick Lacruche, group vice president in charge of security, told reporters that most customers used this system. “But in some cases due to a specific emergency, tests or maintenance that needed doing, it’s possible that some files did not go through secure channels,” he said.

“But... this is very exceptional”.

In its statement, the company said that in the case of a key theft, “the intelligence services would only be able to spy on communications on second generation 2G mobile networks”. “3G and 4G networks are not vulnerable to this type of attack,” it added.

The NSA has come under intense scrutiny both at home and abroad after Mr Snowden leaked documents from June 2013 about government surveillance programmes that sweep up data from Americans as well as foreigners.

The revelations led to a public outcry and strained relations with US allies.

Mr Snowden, who fled the United States, has gained temporary asylum in Russia.

Published in Dawn February 26th , 2015

On a mobile phone? Get the Dawn Mobile App: Apple Store | Google Play

Opinion

Budgeting without people

Budgeting without people

Even though the economy is a critical issue, discussions about it involve a select few who are not really interested in communicating with the people.

Editorial

Iranian tragedy
Updated 21 May, 2024

Iranian tragedy

Due to Iran’s regional and geopolitical influence, the world will be watching the power transition carefully.
Circular debt woes
21 May, 2024

Circular debt woes

THE alleged corruption and ineptitude of the country’s power bureaucracy is proving very costly. New official data...
Reproductive health
21 May, 2024

Reproductive health

IT is naïve to imagine that reproductive healthcare counts in Pakistan, where women from low-income groups and ...
Wheat price crash
Updated 20 May, 2024

Wheat price crash

What the government has done to Punjab’s smallholder wheat growers by staying out of the market amid crashing prices is deplorable.
Afghan corruption
20 May, 2024

Afghan corruption

AMONGST the reasons that the Afghan Taliban marched into Kabul in August 2021 without any resistance to speak of ...
Volleyball triumph
20 May, 2024

Volleyball triumph

IN the last week, while Pakistan’s cricket team savoured a come-from-behind T20 series victory against Ireland,...