3 ms·
Sounds like their EPC/packet core was compromised pretty seriously. Ars article: https://arstechnica.com/information-technology/2022/02/vodafone-portugal-strug
by willidiots 5y ago
Sounds like their EPC/packet core was compromised pretty seriously.
Ars article: https://arstechnica.com/information-technology/2022/02/vodafone-portugal-struggles-to-restore-service-following-cyberattack/ https://arstechnica.com/information-technology/2022/02/vodaf...
"Vaz said the company hadn't received any ransom demand that would indicate it was hit by a ransomware attack. The CEO also said he had no indications the attackers had accessed subscriber information or other sensitive data."
Yet at the same time - "The attack comes a month after the websites of two of Portugal's biggest news outlets—Impresa and later COFINA—were hacked by a ransomware group calling itself Lapsus$."
As to why there's been no discussion, it seems like there just isn't much information to discuss at the moment. Vodafone Portugal's in damage-control mode, they don't want to say more than they have to, and what's been said is in Portuguese.
OP - are you in Portugal? Desculpe if so! I imagine this is a big deal in-country.
- libertine 5y agoI'm portuguese, and this subject was in the news for some days. It was followed by the news outlets like you've said, but still, both events are quite rare to be mentioned in the media. For example, four or five years ago there were some ransomware attacks but it never reached the media. What's more troublesome about Vodafone attack was that it affected some emergency services, and hospitals, that used Vodafone for communications -> this is what is being deemed as secondary to international news. Was this just colateral damage from a random attack to Vodafone? Or was Vodafone attacked because they knew some emergency services were dependent on Vodafone? Where is the line that separates an attack to emergency services/hospitals, which shouldn't be taken lightly, from a regular attack to a big company that happens to provide services to key operations in a country? Was it a criminal offense, or a terrorist attack? All of this could be a coincidence of course, but due to the range and the damage of the attack, this must be investigated and it's a big deal to Portugal. I don't think there were any deaths directly related to this attack, especially because those emergency services were quick to switch to other communication solutions, but the headlines could be flipped around: Portuguese Emergency Services were disrupted after cyberattack to Vodafone Portugal.
- trompetenaccoun 5y agoRansomware attacks are often hushed up. I understand why this is done but the danger here is that they're a lot more common than the public is aware of and nothing much is done about it because there isn't enough political pressure.
- g_p 5y ago> Sounds like their EPC/packet core was compromised pretty seriously. Given the issues affected fixed voice, TV, and value added services like voicemail, I wonder if it was upstream of the EPC in the OSS/BSS environment like the customer database? An issue in the EPC wouldn't usually take out fixed line voice and digital TV services. Maybe a single point of failure in their enabling IT?
- willidiots 5y agoOh, I missed the TV etc. impact - risk of idle speculation, I suppose. Yeah, OSS/BSS or enabling IT seems more likely, though I'm struggling to understand how a fallback to 3G would fix that. Supposedly customer information wasn't compromised. One can hope that Vodafone will provide a decent external postmortem given the impact to Portuguese emergency services etc.