Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Deutsche Telecom Spied on Employees, Journalists

Major German service provider violated privacy laws by analyzing phone records in an attempt to stop leaks to the press

Deutsche Telekom, Germany's largest telecommunications service provider, is facing allegations that its officers misused phone records to find the source of leaks to the press.

The allegations were revealed in Saturday's edition of the German magazine, Der Spiegel, which discovered that Deutsche Telekom had hired a third-party consultant to correlate phone records in an effort to pinpoint calls between company executives and the business press.

Monitoring of employee phone records is legal in Germany, as it is in the United States. However, German law does give employees some right to privacy if the company allows workers to use their business phones for personal calls, which Deutsche Telekom does. The service provider may also have violated German "telecommunications secrecy" laws, which provide for criminal penalties if a telecommunications company misuses the data it collects on its users and customers.

German journalists also are calling for an investigation into potential violations of laws protecting freedom of the press. Reporters, they say, should have the right to call any source without fear that their calls will be monitored or blocked.

The case is reminiscent of the scandal at Hewlett-Packard in 2006, when officials were accused of hiring private investigators to illegally collect data on employees and journalists in an effort to stop a leak to the press. Despite criminal charges and several lawsuits in the HP case, the company has successfully avoided court penalties and the executives involved were given light sentences of community service. (See HP Under Inquiry in Media-Leak Scandal and California Judge Dismisses All Charges Against HP's Dunn; Three Others Cut Deals.)

Similarly, Deutsche Telekom is unlikely to face any court action, said German legal expert Thomas Hoeren in a radio interview.

"The interesting problem in this case is that state attorneys are now investigating what happened at Deutsche Telekom, but this can only lead to a punishment for individuals acting as representatives of Deutsche Telekom. The company as such is out of bounds," Hoeren said.

"What people now want are increased sanctions against the company, not just against the individuals behind the company. In the current situation, Deutsche Telekom can only get a fine of perhaps €25,000 [US$39,000], which is nothing for them."

Still, the service provider faces a good deal of negative publicity that could affect confidence in the publicly held company and might cause some loss of customers, according to news reports.

Theo Kitz, analyst of Merck Finck & Co., said the news wouldn't please customers and that it could lead to further line losses, which already is a key problem for the company in its home market. In March, Deutsche Telekom said it expected its market share of fixed lines in Germany to fall to 73 to 75 percent in 2008 from 82 percent in 2007. By 2010, the incumbent German telecom operator expects market share of around 65 percent.

Der Spiegel uncovered the scandal when it obtained a fax that outlines several different "projects" in which a third party was hired to investigate the activities of company executives, some for as long as a year and a half. The projects called on the consultant to "analyze several hundred thousand landline and mobile connection data sets of key German journalists reporting on Telekom and their private contacts."

Deutsche Telekom said Saturday that it had found indications of the "illegal use" of wireless and fixed-line telecommunications data that occurred in 2005 and 2006. It said it has referred the case to German state prosecutors, who have begun a preliminary probe. The company maintains that there were no wiretaps or eavesdropping involved in the case.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Deutsche Telekom AG (NYSE: DT)
  • Hewlett-Packard Co. (NYSE: HPQ) Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Threaded  |  Newest First  |  Oldest First
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Current Issue
    2020: The Year in Security
    Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
    Flash Poll
    Assessing Cybersecurity Risk in Today's Enterprises
    Assessing Cybersecurity Risk in Today's Enterprises
    COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-12512
    PUBLISHED: 2021-01-22
    Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting
    CVE-2020-12513
    PUBLISHED: 2021-01-22
    Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
    CVE-2020-12514
    PUBLISHED: 2021-01-22
    Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd
    CVE-2020-12525
    PUBLISHED: 2021-01-22
    M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
    CVE-2020-12511
    PUBLISHED: 2021-01-22
    Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.