A threat actor using the name IntelBroker listed a collection of Nokia source code on a criminal forum on 4 November 2024. Nokia said its own systems and data had not been affected. Reporting describes the material as coming from a third-party contractor that had been working on internal tools, with access obtained to that contractor’s SonarQube server using default credentials.
Default Credentials, In 2024
If the account of the entry is right, the control that failed was one nobody has considered adequate for decades: a server left on the credentials it shipped with.
It happened at a supplier rather than at Nokia, which is the point. The security of a system is the security of everyone it has delegated work to, and a code-analysis server at a contractor is not in anyone’s inventory.
Nokia’s Denial Is Accurate And Incomplete
Nokia was right that its systems were not breached. Its code was still published.
Both statements can hold at once, and a disclosure that answers only the first leaves the second unaddressed. Graded medium: the entry route is the attacker’s account, and no independent confirmation of the contractor or the credentials has been published.
Compiled from public reporting and Nokia’s statements, listed below. The contractor, the SonarQube server and the default credentials come from the attacker’s account as reported and are not independently confirmed. Corrections: corrections@forensicpost.com.