skip navigation
skip mega-menu

Sim card firm links GCHQ and NSA to hack attacks

However, Gemalto denied that billions of mobile device encryption keys could have been stolen as a result.

The Intercept alleged last week that spies had obtained the "potential to secretly monitor" voice and data transmissions after hacking the firm.

Gemalto operates in 85 countries.

Its clients include AT&T, T-Mobile, Verizon and Sprint among more than 400 wireless network providers across the world.

GCHQ and the NSA have not commented directly on the allegations.

Fake emails

In a statement, Gemalto said it had carried out a "thorough investigation" following the claims, which were based on documents leaked by whistleblower Edward Snowden.

"The investigation into the intrusion methods described in the document and the sophisticated attacks that Gemalto detected in 2010 and 2011 give us reasonable grounds to believe that an operation by NSA and GCHQ probably happened," the company said.

It highlighted two "particularly sophisticated intrusions" that it suggested the agencies were responsible for.

It said the first had involved a breach of one of its French offices, where hackers had attempted to spy on messages sent both internally between Gemalto employees and externally to others.

The second, it said, had involved fake emails being sent to one of its customers that appeared to come from a Gemalto address. These featured an attachment that triggered a malware download.

"At the time we were unable to identify the perpetrators but we now think that they could be related to the NSA and GCHQ operation," the statement added.

"These intrusions only affected the outer parts of our networks - our office networks - which are in contact with the outside world.

Onion and orange

"The Sim encryption keys and other customer data in general, are not stored on these networks.

"It is important to understand that our network architecture is designed like a cross between an onion and an orange; it has multiple layers and segments which help to cluster and isolate data."

The company added that no breaches had been found in parts of its system used to manage other products including the encryption security it provides for banking cards, ID cards and electronic passports.

The statement appears to contradict claims made in leaked materials published by the Intercept.

The news site published a presentation slide, allegedly sourced from GCHQ, which stated that agents had "successfully implanted" code in several of Gemalto's machines, compromising its "entire network".

Other documents - said to be from a wiki tool - appeared to confirm that GCHQ agents were monitoring data transmissions by Gemalto employees as part of efforts to create a database of Sim card encryption keys.

Source: BBC News

Subscribe to our newsletter

Sign up here