Categories: Security

Attackers ‘Steal’ 900GB Of Data From Phone Hacker Cellebrite

Mobile forensics firm Cellebrite has had 900 GB of data stolen from one of its servers in a hack attack, including customer information and technical product data.

The Israeli company is extremely popular in the world of mobile phone hacking, especially with military and law enforcement, and rose to prominence last year after reportedly helping the FBI to crack the iPhone of the San Bernardino terrorist after Apple refused to cooperate.

That was never confirmed or denied by officials, but Cellebrite certainly has the credentials to be involved having previously worked with the Dutch police in a similar matter.

“Unauthorised access”

In a statement on its website Cellebrite says that it experienced “unauthorised access to an external web server” and is now investigating the scale of the  breach.

“The impacted server included a legacy database backup of my.Cellebrite, the company’s end user license management system,” the statement says.

“The company had previously migrated to a new user accounts system. Presently, it is known that the information accessed includes basic contact information of users registered for alerts or notifications on Cellebrite products and hashed passwords for users who have not yet migrated to the new system.

“To date, the company is not aware of any specific increased risk to customers as a result of this incident; however, my.Cellebrite account holders are advised to change their passwords as a precaution.”

The company also says it is in the process of notifying all customers believed to be affected and is assisting the “relevant authorities” with their investigation.

According to Motherboard, to which the stolen data was delivered, the information included evidence files from seized mobile phones and logs from Cellebrite devices. The site also confirmed the legitimacy of the email addresses by attempting to create new Cellebrite accounts, but being unable to do so at the emails were already in use.

Such a breach certainly isn’t ideal for a company in Cellebrite’s line of work. It’s most popular product is something called a Universal Forensic Extraction Device (UFED), capable of extracting, decoding and analysing digital mobile data.

After a turbulent 12 months in the cyber security industry, where businesses and consumers were consistently under attacks, 2017 isn’t looking like being any different.

In the last two weeks alone we’ve heard reports of ransomware targeting Linux users and MacOS users being hit with Denial-of-Service attacks, which makes initiatives such as GCHQ’s Cyber Accelerator programme more vital than ever.

Think you’re a cyber security whizz? Try our quiz!

Sam Pudwell

Sam Pudwell joined Silicon UK as a reporter in December 2016. As well as being the resident Cloud aficionado, he covers areas such as cyber security, government IT and sports technology, with the aim of going to as many events as possible.

Recent Posts

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

4 hours ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

5 hours ago

LastPass Separates From Parent After Security Incidents

New chapter for LastPass as it becomes an independent company to focus on cybersecurity, after…

7 hours ago

US To Ban Huawei, ZTE From Certifying Wireless Kit

US FCC seeks to ban Chinese telecom firms at centre of national security concerns from…

11 hours ago

Anthropic Launches Enterprise-Focused Claude, Plus iPhone App

Two updates to Anthropic's AI chatbot Claude sees arrival of a new business-focused plan, as…

13 hours ago