Nokia is investigating whether there was a breach at a third-party supplier, following allegations by a hacker of selling stolen company source code.

"Nokia is aware that an unauthorized user has claimed to have accessed certain third-party data and possibly data Nokia," the company told BleepingComputer.
“Nokia takes this allegation seriously and is investigating it. To date, our investigation has not found any evidence that any of our systems or data are affected. We continue to monitor the situation closely“.
See also: Los Angeles: HACLA breached – Cactus ransomware responsible?
The attacker appears to be IntelBroker, who has repeatedly reported breaching several major companies. Among his victims are DC Health Link, Hewlett Packard Enterprise (HPE), Weee!.Most recently, he leaked data from companies including T-Mobile, AMD, and Apple, which was stolen from a third-party SaaS vendor.
Now, it claims to be selling Nokia source code that was stolen after was breached . This vendor reportedly works directly with Nokia to help develop some internal tools.
IntelBroker states that the stolen data contains SSH keys, source code, RSA keys, BitBucket logins, SMTP accounts, webhooks, and hardcoded credentials.
See also: Interbank revealed that it suffered a data breach
According to BleepingComputer, IntelBroker accessed the third-party vendor's SonarQube server using default credentials, which allowed it to download Python projects from customers, including those belonging to Nokia.
As the digital landscape continues to evolve and threats become more sophisticated, it is important for companies to remain vigilant and take proactive measures to protect themselves.

Regular vulnerability assessments, frequent security updates, and ongoing employee training should be an integral part of any organization’s cybersecurity strategy. Additionally, companies should forge strong partnerships with reputable cybersecurity companies and regularly review and update their security protocols to stay ahead of potential threats.
See also: Free: French ISP announces customer data breach
By prioritizing cybersecurity , companies can not only protect their own assets, but also maintain the trust of their customers and investors.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
