Supply chain
⛓ Supply Chain
Truecaller Third-Party Breach (May 2019)
Primary Source ↗Incident Details
Truecaller Users’ Phone Numbers & Email IDs For Sale on Dark Web. Truecaller Number Search App: The caller ID company with more than millions of users in India caters to mobile payment and messaging service also. Truecaller, a caller ID company with access to email IDs and mobile numbers of millions of users, has been hit with fresh allegations of letting its data sell on the dark web. The data is available to any person willing to pay up to Rs 1.5 lakh for data of Indian users, while the amount goes up to a staggering 25,000 euros (Rs 19.4 lakh) for users from other countries. These allegations were revealed in an ET report on Wednesday, bringing to light another data breach to hit users across the world.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- not disclosed
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2019-05-01 Breach occurred
- 2019-05-22 Publicly disclosed