CSIDB logo
Incident

Cosmote

Incident posture

Attack window
Sep 2020
Location
Greece
Status
Historical
CIA posture
Available to members
Updated
2026-03-09 21:27

Linked entities

Victim
Cosmote
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Sep 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major Greek telecommunications provider experienced a cybersecurity incident where attackers accessed customer call records over a five-day period. The breach originated through a third-party system, likely based in Lithuania, compromising metadata including phone numbers, call timestamps, duration, device specifications, subscriber identifiers, demographic information, revenue metrics, location coordinates, and service plans—though no personally identifiable names were exposed. This unauthorized access impacted thousands of subscribers' telecommunications activity data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early September 2020, Cosmote, Greece’s largest mobile network operator, experienced a cyber attack that compromised customer data over a five-day period from September 1 to September 5. The breach involved unauthorized access to telecommunications records through an intrusion traced to a third country, with Lithuania identified as the most likely origin point. Attackers exfiltrated a file containing granular call detail records and subscriber information from Cosmote’s systems. The company publicly disclosed the incident on October 16, 2020, confirming the exposure of thousands of customers’ data but emphasizing that names and surnames were not included in the compromised dataset. The intrusion timeline and geographic attribution were confirmed during Cosmote’s investigation, though specific technical vectors used by the attackers remained undisclosed.

The breached file contained multiple categories of sensitive subscriber information, including telephone numbers, dates, times, and durations of calls made or received during the attack window. Additionally, it exposed device types, International Mobile Subscriber Identity (IMSI) numbers, demographic attributes such as age and gender, and commercial metrics like Average Revenue Per User (ARPU). The dataset also incorporated network infrastructure details through base station coordinates and specifics about subscribers’ mobile tariff plans. While the absence of direct personal identifiers mitigated immediate identity theft risks, the combination of technical and behavioral metadata created significant privacy concerns due to potential profiling capabilities. Cosmote did not report whether the data appeared in illicit forums or whether regulatory penalties resulted from the breach, focusing its communication on the factual scope of the exposure as verified through internal forensic analysis.

Sources

Sources available to members: 2 sources.

CSIDB