Orange Belgium Hacked - Customer Data Stolen

Orange Belgium, a subsidiary of telecommunications giant Orange Group, has disclosed that the personal data of around 850,000 Belgian customers have been hacked by criminals using the French telecoms operator Orange on Wednesday 20th August. 

The telecoms company said it identified the incident in late July, and it immediately activated its response plan and notified the relevant authorities.

Orange, which serves more than 290 million customers globally, has warned that some services could be affected by its response to the incident, though it did not disclose the precise nature of the attack.

In an email sent to affected customers at Orange Belgium it said hackers had gained access to names, telephone numbers, SIM card details, tariff plans and the Personal Unlocking Key (PUK) codes of users.Confusingly, Orange says the no passwords, email addresses or financial information had been stolen.

A ransomware group named WarLock has claimed to have stolen data from Orange. Some of the files made public by the hackers suggest that the compromised data relates to customers in France.

Orange's handling of the incident was met with sharp criticism from some of Belgium's cyber security community
In a LinkedIn message, Inti De Ceukelaire, chief hacker at Belgian bug-bounty platform Intigriti, called the company’s response “very disappointing,” accusing Orange of following “the same old corporate PR playbook” to protect its brand rather than its customers. De Ceukelaire warned that the dedicated information page published by Orange downplayed the real risks, such as SIM swapping and number theft, while shifting the burden onto users to guard against phishing. 

Orange, one of the biggest mobile service providers in both Europe and Africa, announced in March that it had suffered a cyber attack affecting users in Romania.

This latest breach comes as European regulators and telecoms operators step up scrutiny of cyber security standards amid a rise in large-scale data leaks targeting critical infrastructure.  

Orange  |   Politico  |   Security Week  |  Bleeping Computer  |  Inti De Ceukelaire  |   TheFastMode  

Image: @OrangeBEFR

You Might Also Read: 

Mobile Devices: A Growing Target For Cyber Attacks:


If you like this website and use the comprehensive 8,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Directors Face Serious Risks As Cyber Attacks Increase
How To Choose The Best CDR Solution For Your Business »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

MetaCompliance

MetaCompliance

MetaCompliance is a cyber security and compliance organisation that helps transform your company culture and safeguard your data and values.

CERT-FR

CERT-FR

CERT-FR is the French national government computer security incident response team.

Clavister

Clavister

Clavister is a network security vendor delivering a full range of network security solutions for both physical and virtualized environments.

Jscrambler

Jscrambler

Jscrambler addresses all your JavaScript and Web application protection needs.

Mission Secure (MSi)

Mission Secure (MSi)

MSi is a specialized provider of next generation cyber defense solutions protecting control systems and critical physical assets in energy, transportation and defense.

Payatu

Payatu

Payatu Technologies is a security testing and services company specialized in Software, Application and Infrastructure security assessments and deep technical security training.

Cytomic

Cytomic

Cytomic is the business unit of Panda Security specialized in providing advanced cybersecurity solutions and services to large enterprises.

Sadoff E-Recycling & Data Destruction

Sadoff E-Recycling & Data Destruction

Sadoff E-Recycling and Data Destruction protect the environment and your data with proven and trusted electronics recycling and data destruction services.

ARCON

ARCON

ARCON offers a proprietary unified governance framework, which addresses risk across various technology platforms.

CleanCloud by SEK

CleanCloud by SEK

CleanCloud by SEK is a CSPM product focused on public cloud data protection and security regulations, with over 400 compliance checks for the market's leading frameworks and regulations.

Cyber Chasse

Cyber Chasse

Cyber Chasse is an IT consulting and staffing company offering a full range of cybersecurity solutions, contract staffing services and online training courses.

Kriptos

Kriptos

Kriptos helps businesses improve their cybersecurity, risk, and compliance strategies by locating critical information through a technology that automatically classifies and labels documents using AI.

Techmentum

Techmentum

At Techmentum, our mission is to utilize technology to help companies succeed. Our expertise includes fully managed IT services, cybersecurity, cloud, and custom technology solutions.

Iron EagleX

Iron EagleX

Iron EagleX deliver engineering solutions in cloud computing, big data, cyber, and machine learning technologies to US Government customers.

GrayHats

GrayHats

GrayHats is a platform-based cybersecurity company devoted to delivering comprehensive, scalable, and proactive protection for businesses in an ever-evolving threat landscape.

Cyber Husky

Cyber Husky

Cyber Husky is an agile technology company that specializes in cloud solutions, cybersecurity, and managed IT services.