Salt: cyber attack and theft of mobile customer data (cross-border guide)

Headquarters of a mobile telecommunication operator in Switzerland involved in a cyber attack

The Salt telephone operator victim of a cyber-attack. Personal data of some mobile customers in Switzerland was stolen. The Federal Appointee has been notified.

Context

In a nutshell

  • Salt operator is the victim of a cyber attack
  • Subtracted personal data of some mobile customers
  • The Federal Data Protection Officer has been notified
  • No password or bank details compromised

Key facts

  • What: Cyberattack and theft of personal data
  • When: Friday afternoon
  • Where: Switzerland
  • Who: Salt Telephone Operator

The telephone operator salt was the victim of a cyber attack that led to the theft of personal data of some mobile phone customers in Switzerland. The company confirmed the incident by informing the affected customers during the afternoon of Friday. Information that has been stolen from the systems includes users' first and last names, dates of birth, postal addresses, email addresses and mobile phone numbers associated with mobile phone users.

Details on stolen information and notification

At the moment, the authorities and the company have not yet specified precisely how many people were affected by this cyber attack in Switzerland, nor has the exact time or day of the intrusion into Salt's computer systems been disclosed. However, the telephone operator wanted to clarify in a timely manner that the most sensitive customer data, such as access passwords, bank information or personal credentials, are not compromised in any way.

Operational details

Although the company has ruled out the compromise of particularly critical data such as banking credentials or passwords, the incident raises important questions regarding security management and the protection of personal information in the Swiss telecommunications market. When events of this nature occur, the practical implications for resident citizens mainly concern the risk of exposure to telephone fraud attempts, targeted phishing campaigns, or deceptive communications that exploit the stolen information to appear more reliable. The presence of personal and contact data such as addresses and mobile numbers actually offers malicious actors a privileged channel to attempt scams against the affected users.

Analysis of reporting procedures and the role of federal authorities A relevant aspect of the affair concerns the institutional management of the personal data breach. Salt also proceeded to notify the incident to the Federal Data Protection and Information Commissioner, who confirmed having received the report directly from the telephone company. According to what was specified by Salt, this communication to the authorities took place on a voluntary basis. This is a specific procedure that is adopted when the company believes that the actual risks to the fundamental rights and personality of the individuals involved are not particularly high. This scenario distinguishes the episode from other situations in which notification to the competent authorities is strictly mandatory by law based on the severity of the compromise of corporate and personal data.

Recommended tools

For an updated estimate, use the net salary calculator and the CHF-EUR exchange comparator.

Key points

In light of the cyber attack suffered by the salt operator and the consequent dissemination of personal information, customers who have received the communication from the company must adopt prudent behaviour in the management of their daily communications. The operator himself formally invites all users to pay the utmost attention to any messages, calls or emails that may be suspicious. In particular, it is advisable to always verify the authenticity of the messages received, avoiding clicking on unknown links or providing additional personal information even if the senders seem to refer to correct personal data previously stolen during the computer intrusion into the telephone company's systems.

Practical procedures and recommended checks for consumers

For those who want to deepen the protection of their digital data and monitor their position in the context of telecommunication services in Switzerland, it is useful to regularly consult the support tools and information guides available online. Prevention remains the main tool to defend against fraud attempts related to the theft of personal data from company databases. For more information on digital services and to better manage your users in Switzerland, you can consult our dedicated tools, such as telephony.

Source: rsi.ch

Frequently Asked Questions
What personal data of mobile customers was stolen in the cyber attack on salt?
During the cyber attack that took place on Friday afternoon against the telephone operator Salt in Switzerland, several personal data of mobile phone customers were stolen. Information stolen includes users' first and last names, dates of birth, mailing addresses, email addresses, and mobile phone numbers associated with utilities.
Have Salt customers' passwords and bank details been compromised?
No, the telephone operator salt has promptly confirmed that the data considered to be the most sensitive of the customers is not compromised in any way. Specifically, the access passwords, banking information and personal credentials used for logins on the various digital portals are totally safe and have not been breached during the intrusion into the systems.
Which authorities were informed of the data breach suffered by salt?
Salt notified the Federal Data Protection Officer, who confirmed that he had received the report directly from the telephone company. This communication took place on a voluntary basis, a procedure adopted when the company considers that the actual risks to the fundamental rights and personality of the people involved are not particularly high.

Related articles