Vodacom number leak update
Vodacom has responded to recent reports that it is injecting subscriber information in the data being sent to servers when a web page is requested.
The mobile network operator said it is still investigating the issue as a matter of urgency, but wanted to reassure its customers that their information is not being routinely shared with all websites.
Earlier today (Wednesday, 29 October 2014), MyBroadband reported that Vodacom was modifying the HTTP headers of users on its data network to inject information which any web server could read.
Among the details included in the modified headers were subscriber phone numbers, and a number (IMEI/SV) that could be used to uniquely identify a subscriber’s device.
However, Vodacom said that this information was not being shared with all websites, nor was it intended to be shared with all web servers.
“Header enrichment is not our default operation,” Vodacom said. “We use it for a select number of Vodacom and trusted third-party services, such as charge-to-bill.”
Vodacom will provide a further update once its investigation is complete, the spokesperson said.
More information security news
Vodacom exposing your number to every website you visit
Top-secret South African satellite
Did SA government blow €2-million on spyware?
FNB website exposed private information
Massive privacy, security flaw with Gautrain-linked site