CSIDB logo
Incident

Telefónica

Incident posture

Attack window
Oct 2022
Location
Spain
Status
Historical
CIA posture
Available to members
Updated
2025-10-16 00:00

Linked entities

Victim
Telefónica
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Telefónica experienced a cybersecurity incident involving unauthorized access to router configuration data for a subset of Movistar and O2 customers, compromising technical details such as Wi-Fi network names and passwords. The company confirmed no sensitive personal or financial information was accessed, advising affected users to change their Wi-Fi credentials as a precaution. Immediate corrective measures were implemented to prevent recurrence, with the operator emphasizing that exploiting the stolen data required physical proximity to the compromised networks.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early October 2022, Telefónica detected a cybersecurity incident affecting a group of Movistar and O2 customers in Spain. The breach involved unauthorized access to technical configuration data stored on customer routers, specifically targeting devices linked to users' landline telephone numbers. Attackers compromised details including the router manufacturer, Wi-Fi network name (SSID), Wi-Fi password, unique device identifiers (MAC addresses), and port configuration settings. Telefónica clarified that the intrusion did not extend to sensitive personal or financial information such as customer names, physical addresses, billing details, bank account numbers, or call records. The company identified the incident through its Movistar security team, which monitored unauthorized access attempts to router management interfaces.

Telefónica promptly notified affected customers via direct communication, instructing them to change their Wi-Fi passwords as a precautionary measure. The company emphasized that stolen configuration data alone could not facilitate remote exploitation, as attackers would require physical proximity to the Wi-Fi signal range to misuse the credentials. Immediate containment measures were implemented to prevent recurrence, though technical specifics of these controls were not disclosed publicly. No operational disruptions to telecommunications services were reported. Telefónica’s public statements consistently maintained that the incident’s impact was confined to non-identifiable technical parameters and posed no material risk to customer privacy or financial security. The breach resolution timeline and total number of affected customers were not disclosed in available reporting.

Sources

Sources available to members: 1 source.

CSIDB