Desk live·
ForensicPost
Breaches/Supply chain/File 24-1104

Nokia Source Code Leaked From a Contractor’s Server With Default Logins

IntelBroker advertised Nokia source code in November 2024. Nokia said its own systems were not affected; reporting traced the material to a third-party contractor’s server reached with default credentials.

Constructed geometry · not a chart of case data
JurisdictionFinlandEspoothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetNokia
ActorIntelBroker
D. Kennedy8 min readConfidence: medium2 sources reviewed

A threat actor using the name IntelBroker listed a collection of Nokia source code on a criminal forum on 4 November 2024. Nokia said its own systems and data had not been affected. Reporting describes the material as coming from a third-party contractor that had been working on internal tools, with access obtained to that contractor’s SonarQube server using default credentials.

Default Credentials, In 2024

If the account of the entry is right, the control that failed was one nobody has considered adequate for decades: a server left on the credentials it shipped with.

It happened at a supplier rather than at Nokia, which is the point. The security of a system is the security of everyone it has delegated work to, and a code-analysis server at a contractor is not in anyone’s inventory.

Nokia’s Denial Is Accurate And Incomplete

Nokia was right that its systems were not breached. Its code was still published.

Both statements can hold at once, and a disclosure that answers only the first leaves the second unaddressed. Graded medium: the entry route is the attacker’s account, and no independent confirmation of the contractor or the credentials has been published.

How we reported this

Compiled from public reporting and Nokia’s statements, listed below. The contractor, the SonarQube server and the default credentials come from the attacker’s account as reported and are not independently confirmed. Corrections: corrections@forensicpost.com.

Sources
  1. Nokia waves off IntelBroker breach claims, says leaked source code came from a third party applicationIT Pro
  2. As Hacker Gives Stolen Data Away, Nokia Issues New Denial StatementForbes
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary