Security29.10.2014

Vodacom number leak update

Vodacom Ball

Vodacom has responded to recent reports that it is injecting subscriber information in the data being sent to servers when a web page is requested.

The mobile network operator said it is still investigating the issue as a matter of urgency, but wanted to reassure its customers that their information is not being routinely shared with all websites.

Earlier today (Wednesday, 29 October 2014), MyBroadband reported that Vodacom was modifying the HTTP headers of users on its data network to inject information which any web server could read.

Among the details included in the modified headers were subscriber phone numbers, and a number (IMEI/SV) that could be used to uniquely identify a subscriber’s device.

However, Vodacom said that this information was not being shared with all websites, nor was it intended to be shared with all web servers.

“Header enrichment is not our default operation,” Vodacom said. “We use it for a select number of Vodacom and trusted third-party services, such as charge-to-bill.”

Vodacom will provide a further update once its investigation is complete, the spokesperson said.

Vodacom exposing your number to every website you visit

Top-secret South African satellite

Did SA government blow €2-million on spyware?

FNB website exposed private information

Massive privacy, security flaw with Gautrain-linked site

Show comments

Latest news

More news

Trending news

Sign up to the MyBroadband newsletter