Attivo Networks Blogs

Telefonica breach leaves data on millions exposed

SC media logo

Hackers exploited a flaw at Spanish operator Telefonica early Monday and likely exposed all the personal data of millions of the company’s customers.

Identity and payment information – including land line and mobile numbers, national ID numbers, addresses, banks, names and records of calls and other data – was exposed, although there is no evidence that any of the data was used in fraudulent activity, according to a report in Telecompaper, which cited El Espanol.

The company reportedly has fixed the flaw.

“Telefonica cannot at present ascertain the potential impact – that will take time to understand,” said Pravin Kothari, founder and CEO of cloud security provider CipherCloud, who noted that Telefonica is a global top 10 telecom company reporting revenue of more than $53 billion. “Surprisingly, the Telefonica customer data was easily downloadable as an unencrypted spreadsheet.”

According to Kothari, the “moral of the story” is that hackers “will get into any network sooner or later.”

If Telefonica’s data had been protected by end-to-end encryption “there would be no breach to report under GDPR,as stolen encrypted data would be unusable,” he said. “Now that GDPR is in effect, the Telefonica customer notifications and follow-up must be done in a compliant and potentially expensive way.”

The Telefonica breach, as well as others that occur in the EU, “now presents the risk of an unknown and potentially expensive GDPR audit,” said Kothari.


Share on:

Free Active Directory Assessment

Get Visibility Into Privilege And Service Account Exposure

For a limited time, Attivo Networks is providing free Active Directory Security Assessments to demonstrate how ADAssessor provides unprecedented and continuous visibility to AD vulnerabilities.

Try Our Endpoint Detection Net (EDN) for Free


Free use offer of our Award-winning security solution to prevent attackers from lateral movement, credential theft, and privilege escalation, fast and easy.

Newsletter Signup

    Yes, please opt me in to receive your quarterly newsletter, event invitations, and product updates.

    I understand that I can opt out at any time, and can refer to Attivo Networks Privacy Policy for more information.
  • This field is for validation purposes and should be left unchanged.

ADSecure 90-Day Free Trial


  • Hide and deny access to AD objects
  • Get alerted on unauthorized queries
  • Attack details easily viewable in dashboard
  • Your data remains on-premise


Leave a Comment

Your email address will not be published.

twenty − five =

Ready to find out what’s lurking in your network?

Scroll to Top