Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Darkly)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Uncategorized
  3. One of the Finnish Government ICT Centre (Valtori) MDM services was compromised.

One of the Finnish Government ICT Centre (Valtori) MDM services was compromised.

Scheduled Pinned Locked Moved Uncategorized
infoseccybersecuritycompromisebreach
4 Posts 2 Posters 2 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Harry SintonenH This user is from outside of this forum
    Harry SintonenH This user is from outside of this forum
    Harry Sintonen
    wrote last edited by
    #1

    One of the Finnish Government ICT Centre (Valtori) MDM services was compromised. Apparently the attacker(s) employed a vulnerability that did not have security fix available at the time of the breach.

    The attacker extracted at least name, email address, phone number and device information for the impacted users. Actual mobile devices have not been known to be targeted.

    Valtori provides service to 77000 users. While not all of them had devices under the affected system, this is still quite concerning.

    Source: https://valtori.fi/-/osassa-valtionhallinnon-mobiililaitehallintaa-tietomurto-hyokkaajan-toiminta-estetty (in finnish)

    #infosec #cybersecurity #compromise #breach

    Harry SintonenH 2 Replies Last reply
    1
    0
    • Harry SintonenH Harry Sintonen

      One of the Finnish Government ICT Centre (Valtori) MDM services was compromised. Apparently the attacker(s) employed a vulnerability that did not have security fix available at the time of the breach.

      The attacker extracted at least name, email address, phone number and device information for the impacted users. Actual mobile devices have not been known to be targeted.

      Valtori provides service to 77000 users. While not all of them had devices under the affected system, this is still quite concerning.

      Source: https://valtori.fi/-/osassa-valtionhallinnon-mobiililaitehallintaa-tietomurto-hyokkaajan-toiminta-estetty (in finnish)

      #infosec #cybersecurity #compromise #breach

      Harry SintonenH This user is from outside of this forum
      Harry SintonenH This user is from outside of this forum
      Harry Sintonen
      wrote last edited by
      #2

      This Ivanti Endpoint Manager Mobile (IPMM) security advisory seems to fit the timeline of the incident: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US

      1 Reply Last reply
      0
      • Harry SintonenH Harry Sintonen

        One of the Finnish Government ICT Centre (Valtori) MDM services was compromised. Apparently the attacker(s) employed a vulnerability that did not have security fix available at the time of the breach.

        The attacker extracted at least name, email address, phone number and device information for the impacted users. Actual mobile devices have not been known to be targeted.

        Valtori provides service to 77000 users. While not all of them had devices under the affected system, this is still quite concerning.

        Source: https://valtori.fi/-/osassa-valtionhallinnon-mobiililaitehallintaa-tietomurto-hyokkaajan-toiminta-estetty (in finnish)

        #infosec #cybersecurity #compromise #breach

        Harry SintonenH This user is from outside of this forum
        Harry SintonenH This user is from outside of this forum
        Harry Sintonen
        wrote last edited by
        #3

        Apparently more user information was actually leaked than initially estimated. The current estimates are around 50000 user accounts. This is due to the system not actually deleting the user account from the database when the user is deleted.

        Source: https://valtori.fi/-/tilannepaivitys-30.1.-todetusta-mobiililaitehallinnan-tietomurrosta (in finnish).

        This btw makes the system not GDPR compliant.

        karttuK 1 Reply Last reply
        0
        • Harry SintonenH Harry Sintonen

          Apparently more user information was actually leaked than initially estimated. The current estimates are around 50000 user accounts. This is due to the system not actually deleting the user account from the database when the user is deleted.

          Source: https://valtori.fi/-/tilannepaivitys-30.1.-todetusta-mobiililaitehallinnan-tietomurrosta (in finnish).

          This btw makes the system not GDPR compliant.

          karttuK This user is from outside of this forum
          karttuK This user is from outside of this forum
          karttu
          wrote last edited by
          #4

          @harrysintonen And still no indication of what MDM platform was compromised.

          1 Reply Last reply
          0
          • R ActivityRelay shared this topic
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          Powered by NodeBB Contributors
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • World
          • Users
          • Groups