Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Deutsche Telecom Spied on Employees, Journalists

Major German service provider violated privacy laws by analyzing phone records in an attempt to stop leaks to the press

Deutsche Telekom, Germany's largest telecommunications service provider, is facing allegations that its officers misused phone records to find the source of leaks to the press.

The allegations were revealed in Saturday's edition of the German magazine, Der Spiegel, which discovered that Deutsche Telekom had hired a third-party consultant to correlate phone records in an effort to pinpoint calls between company executives and the business press.

Monitoring of employee phone records is legal in Germany, as it is in the United States. However, German law does give employees some right to privacy if the company allows workers to use their business phones for personal calls, which Deutsche Telekom does. The service provider may also have violated German "telecommunications secrecy" laws, which provide for criminal penalties if a telecommunications company misuses the data it collects on its users and customers.

German journalists also are calling for an investigation into potential violations of laws protecting freedom of the press. Reporters, they say, should have the right to call any source without fear that their calls will be monitored or blocked.

The case is reminiscent of the scandal at Hewlett-Packard in 2006, when officials were accused of hiring private investigators to illegally collect data on employees and journalists in an effort to stop a leak to the press. Despite criminal charges and several lawsuits in the HP case, the company has successfully avoided court penalties and the executives involved were given light sentences of community service. (See HP Under Inquiry in Media-Leak Scandal and California Judge Dismisses All Charges Against HP's Dunn; Three Others Cut Deals.)

Similarly, Deutsche Telekom is unlikely to face any court action, said German legal expert Thomas Hoeren in a radio interview.

"The interesting problem in this case is that state attorneys are now investigating what happened at Deutsche Telekom, but this can only lead to a punishment for individuals acting as representatives of Deutsche Telekom. The company as such is out of bounds," Hoeren said.

"What people now want are increased sanctions against the company, not just against the individuals behind the company. In the current situation, Deutsche Telekom can only get a fine of perhaps €25,000 [US$39,000], which is nothing for them."

Still, the service provider faces a good deal of negative publicity that could affect confidence in the publicly held company and might cause some loss of customers, according to news reports.

Theo Kitz, analyst of Merck Finck & Co., said the news wouldn't please customers and that it could lead to further line losses, which already is a key problem for the company in its home market. In March, Deutsche Telekom said it expected its market share of fixed lines in Germany to fall to 73 to 75 percent in 2008 from 82 percent in 2007. By 2010, the incumbent German telecom operator expects market share of around 65 percent.

Der Spiegel uncovered the scandal when it obtained a fax that outlines several different "projects" in which a third party was hired to investigate the activities of company executives, some for as long as a year and a half. The projects called on the consultant to "analyze several hundred thousand landline and mobile connection data sets of key German journalists reporting on Telekom and their private contacts."

Deutsche Telekom said Saturday that it had found indications of the "illegal use" of wireless and fixed-line telecommunications data that occurred in 2005 and 2006. It said it has referred the case to German state prosecutors, who have begun a preliminary probe. The company maintains that there were no wiretaps or eavesdropping involved in the case.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Deutsche Telekom AG (NYSE: DT)
  • Hewlett-Packard Co. (NYSE: HPQ) Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio
     

    Recommended Reading:

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 8/3/2020
    Pen Testers Who Got Arrested Doing Their Jobs Tell All
    Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
    New 'Nanodegree' Program Provides Hands-On Cybersecurity Training
    Nicole Ferraro, Contributing Writer,  8/3/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Current Issue
    Special Report: Computing's New Normal, a Dark Reading Perspective
    This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
    Flash Poll
    The Changing Face of Threat Intelligence
    The Changing Face of Threat Intelligence
    This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-15058
    PUBLISHED: 2020-08-07
    Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
    CVE-2020-15059
    PUBLISHED: 2020-08-07
    Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
    CVE-2020-15060
    PUBLISHED: 2020-08-07
    Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
    CVE-2020-15061
    PUBLISHED: 2020-08-07
    Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.
    CVE-2020-15062
    PUBLISHED: 2020-08-07
    DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.