Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Deutsche Telecom Spied on Employees, Journalists

Major German service provider violated privacy laws by analyzing phone records in an attempt to stop leaks to the press

Deutsche Telekom, Germany's largest telecommunications service provider, is facing allegations that its officers misused phone records to find the source of leaks to the press.

The allegations were revealed in Saturday's edition of the German magazine, Der Spiegel, which discovered that Deutsche Telekom had hired a third-party consultant to correlate phone records in an effort to pinpoint calls between company executives and the business press.

Monitoring of employee phone records is legal in Germany, as it is in the United States. However, German law does give employees some right to privacy if the company allows workers to use their business phones for personal calls, which Deutsche Telekom does. The service provider may also have violated German "telecommunications secrecy" laws, which provide for criminal penalties if a telecommunications company misuses the data it collects on its users and customers.

German journalists also are calling for an investigation into potential violations of laws protecting freedom of the press. Reporters, they say, should have the right to call any source without fear that their calls will be monitored or blocked.

The case is reminiscent of the scandal at Hewlett-Packard in 2006, when officials were accused of hiring private investigators to illegally collect data on employees and journalists in an effort to stop a leak to the press. Despite criminal charges and several lawsuits in the HP case, the company has successfully avoided court penalties and the executives involved were given light sentences of community service. (See HP Under Inquiry in Media-Leak Scandal and California Judge Dismisses All Charges Against HP's Dunn; Three Others Cut Deals.)

Similarly, Deutsche Telekom is unlikely to face any court action, said German legal expert Thomas Hoeren in a radio interview.

"The interesting problem in this case is that state attorneys are now investigating what happened at Deutsche Telekom, but this can only lead to a punishment for individuals acting as representatives of Deutsche Telekom. The company as such is out of bounds," Hoeren said.

"What people now want are increased sanctions against the company, not just against the individuals behind the company. In the current situation, Deutsche Telekom can only get a fine of perhaps €25,000 [US$39,000], which is nothing for them."

Still, the service provider faces a good deal of negative publicity that could affect confidence in the publicly held company and might cause some loss of customers, according to news reports.

Theo Kitz, analyst of Merck Finck & Co., said the news wouldn't please customers and that it could lead to further line losses, which already is a key problem for the company in its home market. In March, Deutsche Telekom said it expected its market share of fixed lines in Germany to fall to 73 to 75 percent in 2008 from 82 percent in 2007. By 2010, the incumbent German telecom operator expects market share of around 65 percent.

Der Spiegel uncovered the scandal when it obtained a fax that outlines several different "projects" in which a third party was hired to investigate the activities of company executives, some for as long as a year and a half. The projects called on the consultant to "analyze several hundred thousand landline and mobile connection data sets of key German journalists reporting on Telekom and their private contacts."

Deutsche Telekom said Saturday that it had found indications of the "illegal use" of wireless and fixed-line telecommunications data that occurred in 2005 and 2006. It said it has referred the case to German state prosecutors, who have begun a preliminary probe. The company maintains that there were no wiretaps or eavesdropping involved in the case.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Deutsche Telekom AG (NYSE: DT)
  • Hewlett-Packard Co. (NYSE: HPQ) Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio
     

    Recommended Reading:

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Oldest First  |  Newest First  |  Threaded View
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 8/10/2020
    Pen Testers Who Got Arrested Doing Their Jobs Tell All
    Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
    Researcher Finds New Office Macro Attacks for MacOS
    Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Current Issue
    Special Report: Computing's New Normal, a Dark Reading Perspective
    This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
    Flash Poll
    The Changing Face of Threat Intelligence
    The Changing Face of Threat Intelligence
    This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-17479
    PUBLISHED: 2020-08-10
    jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
    CVE-2020-17480
    PUBLISHED: 2020-08-10
    TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
    CVE-2020-9078
    PUBLISHED: 2020-08-10
    FusionCompute 8.0.0 have local privilege escalation vulnerability. A local, authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.
    CVE-2020-9243
    PUBLISHED: 2020-08-10
    HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a denial of service vulnerability. The system does not properly limit the depth of recursion, an attacker should trick the user installing and execute a malicious application. Successful exploit could cause a denial of service co...
    CVE-2020-9245
    PUBLISHED: 2020-08-10
    HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0.160(C00E160R2P8) have a denial of service vulnerability. Certain system configuration can be modified because of improper authorization. The attacker could trick the user installin...