CSIDB logo
Incident

Telekom Slovenije

Incident posture

Attack window
Feb 2025
Location
Slovenia
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 17:17

Linked entities

Victim
Telekom Slovenije
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted Telekom Slovenije through a breach of its support system used for incident management and fault resolution. Upon detection, the company activated measures to contain and halt the intrusion, working alongside relevant authorities and cybersecurity experts to investigate the incident. Although the operator stated there was no direct breach of subscriber or communication databases, a package of 385 files reportedly surfaced on the dark web, containing personal data such as subscriber addresses, phone numbers, IP addresses, work orders, and records from its Kosovo-based subsidiary IPKO, including speed camera images. No ransom demand has been disclosed by the attackers at that stage.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On 1 February 2025, Telekom Slovenije publicly acknowledged a cyberattack targeting the company's internal infrastructure, prompting immediate response measures and an ongoing investigation in coordination with competent authorities and cybersecurity experts. The company stated that the intrusion was confined to a support system used for incident management and error resolution, and that no breach of subscriber data repositories or communications records had occurred, according to their official communication published on the Ljubljana Stock Exchange website.

However, independent reporting by Finance indicated that a package of 385 files had already appeared on the dark web on Tuesday, prior to the company's public disclosure, and was being offered for transfer by unknown actors. The editorial team of Finance reportedly obtained these files and found that they contained personal information belonging to Telekom subscribers, including physical addresses, telephone numbers, and IP addresses. The leaked material also reportedly included records of customers and other contractual partners. Among the documents were goods receipt forms, work orders for the activation of new subscribers, and records related to subscribers applying for specific benefits. Additionally, the compromised data contained photographs or recordings of speeding drivers captured on highways. A substantial portion of the leaked documents reportedly concerned the operations of Telekom's subsidiary IPKO, which provides telecommunications services in Kosovo. At the time of reporting, the attackers had not published any ransom demands or other specific claims.

In response to detecting the attack, Telekom Slovenije immediately implemented all necessary measures to contain and halt the incident, actions which the company stated were designed to prevent the attack from continuing or spreading further across their systems. The company emphasized that it was collaborating with relevant authorities and cybersecurity specialists to conduct a comprehensive investigation into the incident. Due to the investigative interest, Telekom Slovenije indicated that it could not disclose additional details at that time. The juxtaposition between the company's public assurances regarding the security of subscriber databases and the appearance of subscriber-related data on the dark web established the central factual contradiction of the early reporting on this incident. The incident represented one of the notable cybersecurity events affecting Slovenian critical infrastructure, though the full scope of the data exposure, the identity of the threat actors, and the ultimate impact on Telekom Slovenije's operations and customer trust remained subjects of continuing investigation as of the article's publication date.

Sources

Sources available to members: 1 source.

CSIDB