“`html

Data Brokers Leak EU Officials’ Location Data: National Security Implications

In a disturbing breach of privacy and national security, data brokers are actively selling location data, including the movements of high-ranking officials within the European Union and NATO. Based on analysis of publicly available data, the incident has been attributed to a network of data brokers operating with a high degree of confidence.

The Attack

The core of the breach lies in the aggregation and sale of mobile device location data, initially collected for advertising purposes. These data brokers obtain their data through various means, including partnerships with advertising networks, apps that track user locations, and data scraping operations. Two datasets, containing 278 million mobile device location pings from Belgium, demonstrate the scale of the operation. These records offer near-precise location data, capable of creating detailed movement profiles. The investigation revealed approximately 2,000 location data points from 264 devices within the EU Commission’s headquarters and 9,600 pings from 543 devices within the NATO headquarters.

The Actors

The actors behind this data harvesting are a network of data brokers, who specialize in collecting, aggregating, and selling user data. While the exact identity of the brokers is unknown at this time, their business model relies on exploiting vulnerabilities in the digital advertising ecosystem. Previous investigations have shown that these brokers operate with little regard for privacy regulations, selling data to the highest bidder, including potentially hostile state actors. These are likely commercial entities rather than organized cybercrime groups.

The Fallout

The leak exposed the location data of EU and NATO officials, including details of their private addresses. The data could reveal sensitive information about their movements, potentially making them targets for espionage, extortion, or physical threats. Following the breach, the EU Commission issued new guidelines for advertising tracking on its employees’ devices. The incident highlights the vulnerability of high-profile individuals to data exploitation.

The EU Commission is responding by informing other EU bodies and member states, and calls for strict restrictions on the collection and use of movement data. Lawmakers are discussing a response that treats this as a pressing security threat, rather than merely a data privacy concern. In Helsinki, the Hybrid CoE, an organization researching hybrid threats for the EU and NATO, confirmed that mobile location data could be misused by adversaries.

Cybercrime Economics

  • Data Acquisition Costs: Relatively low, depending on the sources (advertising networks, app data).
  • Data Aggregation/Processing Costs: Moderate, as large datasets require infrastructure and skilled personnel.
  • Data Sale Revenue: Highly variable. The value of the data depends on the buyer and sensitivity.
  • Potential Damage: Severe, depending on the use of the data (espionage, extortion, physical harm).

This incident is part of the “Databroker Files,” an investigative project by netzpolitik.org, Bayerischer Rundfunk, and international media partners. This project has won several awards.

“`


Leave a Reply

Your email address will not be published. Required fields are marked *