A new data leak case has come to light after a Russian security researcher revealed that hardware used by Russian authorities to monitor internet traffic was leaking data . The equipment in question consisted of SORM devices.
All Russian internet service providers (ISPs) and companies must install devices in their data centers to comply with local legislation.
SORM stands for “System for Operative Investigative Activities.” SORM devices are hardware devices that allow Russian authorities to connect to devices, record data , and then retrieve that data at a later time.
The newest devices, SORM-3, are able to record various details, such as IP addresses, MAC addresses, codes , ICQ usernames and email addresses.

Data leak
Last Sunday, August 25, the Chaos Constructions security conference took place, where a Russian security researcher, Leonid Evdokimov, revealed that some of these devices are responsible for the data leak.
The researcher said he discovered 30 SORM devices installed on the network of 20 Russian ISPs with servers that were not password-protected.
The FTP servers contained files from previous surveillance by Russian authorities. Some of the data included and leaked online is as follows:
–information for residents of the city of Sarov (formerly Arzamas-16).
-usernames from the ICQ platform, IMEI numbers and phone numbers of hundreds of Moscow residents.
– router MAC addresses and GPS information for people living in the village of Novosilske.
– and countless GPS information from smartphones using old firmware.
According to his statements, Evdokimov discovered the devices, which were exposing data, in April 2018. In June 2018, he began working with internet service providers to ensure the security of these devices.
However, 6 of the 30 SORM devices remained vulnerable until last Sunday, when Evdokimov announced his discovery at the conference. On Monday, a day after the researcher's presentation, the last 6 devices were patched.
The researcher noted that the vulnerable SORM devices were manufactured by different companies, so the theory that the leak was caused by a default error cannot be true.
