abusesaffiliationarrow-downarrow-leftarrow-rightarrow-upattack-typeburgerchevron-downchevron-leftchevron-rightchevron-upClock iconclosedeletedevelopment-povertydiscriminationdollardownloademailenvironmentexternal-linkfacebookfiltergenderglobegroupshealthC4067174-3DD9-4B9E-AD64-284FDAAE6338@1xinformation-outlineinformationinstagraminvestment-trade-globalisationissueslabourlanguagesShapeCombined Shapeline, chart, up, arrow, graphLinkedInlocationmap-pinminusnewsorganisationotheroverviewpluspreviewArtboard 185profilerefreshIconnewssearchsecurityPathStock downStock steadyStock uptagticktooltiptwitteruniversalityweb

이 페이지는 한국어로 제공되지 않으며 English로 표시됩니다.

기사

2023년 9월 1일

저자:
Aubrey Belford, OCCRP & Stephen Dziedzic, ABC

Citizen Lab uncovers likely exploitation of Telstra-owned mobile network by private spies

"Telstra-owned Pacific mobile network likely exploited by spies for hire", 1 September 2023

A Telstra-owned mobile phone operator in the Pacific Islands has likely been used by private spy firms to track people on the other side of the world and steal their data, according to expert cybersecurity analysis.

Digicel Pacific's network resources appear to have been exploited to target unsuspecting mobile phone users in Africa in a type of attack that has been used in the past by spy-for-hire operations and state actors, according to analysis by the University of Toronto's Citizen Lab shared with the Organized Crime and Corruption Reporting Project (OCCRP) and the ABC.

The revelations come after Telstra purchased Fiji-based Digicel Pacific in July 2022.

The purchase was backed with more than $2 billion in Australian government financing amid fears that China's government could use the network — which operates in six Pacific countries — to carry out spying in the increasingly contested region.

But Citizen Lab's analysis suggests that Telstra has had to contend with another security threat on the network: for-profit surveillance companies.

Typically based in the West, such operations market their services to governments as a way to track criminals and terrorists.

Previous reporting, however, has found these services are frequently used to spy on journalists, activists, and political dissidents.

Messages, calls and location can be intercepted

Using data from the Mobile Surveillance Monitor project, Citizen Lab found that actors who are most likely private spies-for-hire have been attacking phones around the world by leasing or otherwise gaining the use of "global titles" belonging to Digicel Pacific.

Global titles are a kind of address on 3G networks, which can be used to send queries to phones connected to mobile providers anywhere on earth, said Gary Miller, a research fellow at Citizen Lab.

"The attacks seen in the data are blatant and clearly malicious," Mr Miller said.

The Citizen Lab data shows that although Digicel global titles were used, attackers bypassed the company's networks.

After OCCRP and the ABC shared Citizen Lab data with Telstra, the company responded by saying it had already terminated most of the Digicel Pacific global title leases.

The company added that it had cancelled an additional lease after it was brought to their attention by reporters.

Telstra "will be exiting the small number of remaining leases by April 2024, or earlier, if investigations reveal they are acting outside of their contractual obligations," it said.

Ongoing abuse of global titles

The abuse of Digicel Pacific global titles dates back to before Telstra's purchase of the network.

Last October, Telstra acknowledged that their global titles had been used, but said it had acted to "review and reduce" the leasing out of Digicel Pacific's global titles to third parties.

However, a recent Citizen Lab analysis shows Digicel Pacific's global titles continued to be abused after this point.

Suspicious queries surge after lull

The latest analysis shows that Digicel Pacific global titles from five countries — Fiji, Papua New Guinea, Samoa, Tonga, and Vanuatu — were used to lodge over 21,000 suspicious queries in the 12 months to July this year.

Last October alone saw 9,115 such queries, many of them designed to identify individual phones or to find their location.

After a brief lull, suspicious queries surged again in recent months. Nearly 922 likely attacks were recorded in June and July this year, according to the latest available data.

Mr Miller said more could have been done to thwart this activity.

Cancelling the leases is one thing, he said, but the addresses still need to be removed from global networks.

개인정보

이 웹사이트는 쿠키 및 기타 웹 저장 기술을 사용합니다. 아래에서 개인정보보호 옵션을 설정할 수 있습니다. 변경 사항은 즉시 적용됩니다.

웹 저장소 사용에 대한 자세한 내용은 다음을 참조하세요 데이터 사용 및 쿠키 정책

Strictly necessary storage

ON
OFF

Necessary storage enables core site functionality. This site cannot function without it, so it can only be disabled by changing settings in your browser.

분석 쿠키

ON
OFF

귀하가 우리 웹사이트를 방문하면 Google Analytics를 사용하여 귀하의 방문 정보를 수집합니다. 이 쿠키를 수락하면 저희가 귀하의 방문에 대한 자세한 내용을 이해하고, 정보 표시 방법을 개선할 수 있습니다. 모든 분석 정보는 익명이 보장되며 귀하를 식별하는데 사용하지 않습니다. Google은 모든 브라우저에 대해 Google Analytics 선택 해제 추가 기능을 제공합니다.

프로모션 쿠키

ON
OFF

우리는 소셜미디어와 검색 엔진을 포함한 제3자 플랫폼을 통해 기업과 인권에 대한 뉴스와 업데이트를 제공합니다. 이 쿠키는 이러한 프로모션의 성과를 이해하는데 도움이 됩니다.

이 사이트에 대한 개인정보 공개 범위 선택

이 사이트는 필요한 핵심 기능 이상으로 귀하의 경험을 향상시키기 위해 쿠키 및 기타 웹 저장 기술을 사용합니다.