Switzerland Cybersecurity
Salt hit by cyberattack, hackers steal mobile customers' personal data
Mobile operator Salt was the victim of a cyberattack that stole personal data belonging to part of its mobile customer base. The company says passwords and banking data were not compromised, but is urging caution against possible scam attempts.
Mobile phone operator Salt has been the victim of a cyberattack that allowed unknown attackers to steal personal data belonging to part of its mobile customer base. The information that fell into the hackers' hands includes first and last names, dates of birth, postal addresses, email addresses and mobile phone numbers. This is information that, while it does not include financial data, allows the people affected to be precisely identified and linked to an active phone number.
The company informed affected customers directly on Friday afternoon. Salt has not disclosed how many people in Switzerland were affected by the theft, nor when the intrusion into its systems took place.
No sensitive data compromised
According to the operator, the attack did not involve data considered sensitive: passwords, banking information and login credentials were not compromised. Salt is nonetheless advising customers to be wary of any suspicious messages, calls or emails, since the stolen data could be used for scam attempts. In practice, whoever stole the data could now write or call pretending to be a representative of Salt or another company, in order to obtain further personal information.
The data theft was also reported to the Federal Data Protection and Information Commissioner, the authority that oversees compliance with data protection legislation in Switzerland. Asked by RTS, the federal authority confirmed it had received the notification from the telecom operator. Salt states that the disclosure was made voluntarily: this is the procedure a company follows when it judges that the risks to the fundamental rights and personal privacy of those affected are not particularly high. It will now be up to the Federal Data Protection Commissioner to assess whether further measures are needed to protect the people whose data was stolen.
Comments
There are no comments yet. Yours can be the first voice.