One of the Finnish Government ICT Centre (Valtori) MDM services was compromised. Apparently the attacker(s) employed a vulnerability that did not have security fix available at the time of the breach.
The attacker extracted at least name, email address, phone number and device information for the impacted users. Actual mobile devices have not been known to be targeted.
Valtori provides service to 77000 users. While not all of them had devices under the affected system, this is still quite concerning.
Source: https://valtori.fi/-/osassa-valtionhallinnon-mobiililaitehallintaa-tietomurto-hyokkaajan-toiminta-estetty (in finnish)







