A Russian telecom firm that develops expertise to permit telephone and web firms to conduct net surveillance and censorship was hacked, had its web site defaced, and had knowledge stolen from its servers, TechCrunch has discovered.
Based in Russia, Protei makes telecommunications methods for telephone and web suppliers throughout dozens of nations, together with Bahrain, Italy, Kazakhstan, Mexico, Pakistan and far of central Africa. The corporate, now headquartered in Jordan, sells video conferencing expertise and web connectivity options, in addition to surveillance tools and web-filtering merchandise, corresponding to deep packet inspection methods.
It’s not clear precisely when or how Protei was hacked, however a replica of the corporate’s web site saved on the Web Archive’s Wayback Machine exhibits it was defaced on November 8. The web site was restored quickly after.
Throughout the breach, the hacker obtained the contents of Protei’s net server — round 182 gigabytes of recordsdata — together with emails relationship again years.
A duplicate of Protei’s knowledge was supplied to DDoSecrets, a non-profit transparency collective that indexes leaked datasets within the public curiosity, together with knowledge from regulation enforcement, authorities businesses, and firms concerned within the surveillance trade.
Mohammad Jalal, the managing director of Protei’s department in Jordan, didn’t reply to a request for remark concerning the breach.
The id of the hacker is just not identified, nor their motivations, however the defaced web site learn: “one other DPI/SORM supplier bites the mud.” The message seemingly references the corporate’s gross sales of deep packet inspection methods and different web filtering expertise for the Russian-developed lawful intercept system generally known as SORM.
SORM is the primary lawful intercept system used throughout Russia in addition to a number of different nations which use Russian expertise. Cellphone and web suppliers set up SORM tools on their networks, which permits their nation’s governments to acquire the contents of calls, textual content messages and net shopping knowledge of the networks’ clients.
Deep-packet inspection units permit telecom firms to establish and filter net visitors relying on its supply, corresponding to a social media web site or a particular messaging app, and selectively block entry. These methods are used for surveillance and censorship in areas the place freedom of speech and expression are restricted.
Citizen Lab reported in 2023 that Iranian telecoms large Ariantel had consulted with Protei about expertise for logging web visitors and blocking entry to sure web sites. Paperwork seen and printed by Citizen Lab present that Protei touted its expertise’s capacity to limit or block entry to web sites for particular folks or complete swathes of the inhabitants.


